At-least-once message delivery for Resonate channels: every broadcast logged, replayed to reconnecting subscribers
78%
Total Score
healthy
Healthy, with recent releases and active source maintenance despite single-contributor and workflow-pinning concerns.
The package and repository are owned by the same individual account, so the source relationship is clear, but there is no organizational backing to offset the single-maintainer concentration.
All 8 recent commits came from one contributor, so maintenance depends entirely on a single person and has limited handoff resilience.
The repository has no published security policy, leaving vulnerability-reporting expectations and response procedures unclear.
v0.7.0 is not a stable major release, so compatibility may still change before 1.0; it is not marked as a prerelease, which partly offsets that concern.
The single workflow was fully analyzed, uses read-only permissions, and has no reported audit findings or untrusted execution paths. However, both of its 2 action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
predis/predis Version ^2.2 | — | — |
illuminate/support Version ^13.0 | — | — |
webpatser/resonate Version ^0.7.1 | — | — |
illuminate/contracts Version ^13.0 | — | — |
webpatser/fledge-fiber Version ^13.29 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.