The package is clearly licensed and includes repository tests, a changelog, and a matching source repository. It lacks a security policy and has no recent commit or issue activity, leaving maintenance and response capacity weak.
45%
Total Score
33
50
72
75
The package is about 6 years old with 73 releases, but it has had no releases in the last 12 months and its latest release was in July 2020. This is strong evidence of abandonment risk despite the substantial historical release count.
The repository recorded zero commits and zero active maintainers over the last 3 months. This is direct evidence that the project is not currently maintained.
Seven runtime dependencies create a meaningful dependency surface for a library handling mail composition and transport, but the signal does not show an unusual or excessive profile.
The repository is owned by an individual user rather than an organization, and no organizational backing is shown. That makes the absence of current activity more concerning because there is no visible broader maintainer base.
There were no new or closed issues or pull requests in the last month, and no pull requests were merged. Combined with the old last release, this indicates no current project activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
true/punycode Version ^2.1 | — | — |
zendframework/zend-mime Version ^2.5 | — | — |
zendframework/zend-loader Version ^2.5 | — | — |
zendframework/zend-stdlib Version ^2.7 || ^3.0 | — | — |
zendframework/zend-validator Version ^2.10.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.