The package includes a detailed README, tests, and an explicit MIT license, which support adoption. Its Composer install hook should be understood before deploying it because it runs during setup.
62%
Total Score
50
86
67
The package defines a post-autoload-dump lifecycle script, so Composer installation can execute package-controlled code. This is common in PHP packages but adds supply-chain exposure that deserves review.
The registry namespace and repository are owned by the same individual user, which is consistent ownership but provides no organization-backed maintenance structure.
The package is only 51 days old, with 7 releases and a median interval of roughly 52 minutes. That shows active iteration but leaves limited evidence of long-term maintenance and release stability.
One contributor accounts for 100% of the single recent commit. The linked repository is user-owned rather than organization-owned, so there is no shown organizational handoff capacity to compensate for this concentration.
Only 1 commit was recorded in the last 3 months, with 1 active maintainer. Because the project is only 51 days old, this is not evidence of abandonment, but it provides little maintenance history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/mailer Version ^7.0|^8.0 | — | — |
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/mail Version ^11.0|^12.0|^13.0 | — | — |
laravel/prompts Version ^0.3.0 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.