The project includes tests, release notes, a clear MIT license, and active organizational ownership. Its workflows use five unpinned actions and contain a high-confidence unpinned container image plus inherited secrets, so pin this version and review its CI trust boundaries.
78%
Total Score
83
50
100
50
The package has 12 runtime dependencies, including several PHP extensions and Redis-related libraries; this is a meaningful integration surface but not excessive for a queueing library.
Two commits from two active maintainers in the last three months show some ongoing work, though the low volume supports a modest maintenance reservation.
No repository security policy was found, leaving reporting and response expectations undocumented for a library with operational dependencies.
All three workflows were analyzed without untrusted checkouts or script injection, but all five action references are unpinned and the audit found a high-confidence unpinned container image plus inherited secrets. These are meaningful CI supply-chain and credential-hygiene weaknesses, though no dangerous trigger was present.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1 || ^2 || ^3 | — | — |
ramsey/uuid Version ^3.7 || ^4 | — | — |
predis/predis Version ^1.1.10 || ^2.0 | — | — |
monolog/monolog Version ^1.23 || ^2.0 || ^3.0 | — | — |
seld/signal-handler Version 1.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.