The MIT license and compact package structure are reassuring, but the README appears copied from another package and the repository has no security policy. No tests are not a concern for a published Composer artifact, while maintenance remains the main limitation.
58%
Total Score
50
100
81
83
A README is present, but its heading and introductory text describe laravel-amqp rather than this package, reducing documentation transparency. Missing tests and changelog files are normal for a published artifact and are not counted against it.
The source repository is owned by an individual account rather than an organization, so there is no demonstrated organizational backing to compensate for the limited activity.
Only two releases were published, with no releases in the last 12 months after the second release in August 2025. This suggests limited evidence of sustained maintenance.
There were no commits and no active maintainers during the last three months. Combined with the short release history, this is meaningful evidence of weak current maintenance.
Composer build tooling is present, but no security scanning tools were detected. That is a transparency and hygiene gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.9.3 | — | — |
laravel/framework Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.