The MIT license and lack of install-time scripts are reassuring, and the dependency set is small. The published README appears to describe Guzzle rather than this package, weakening transparency for consumers.
42%
Total Score
0
100
50
75
This is the only release, published in April 2020, with no releases in the last 12 months; that long lack of release activity is a strong abandonment concern.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with a project that is no longer being maintained.
A README and changelog are present, but the README excerpt describes Guzzle rather than this WordPress mail plugin. The absence of package tests is normal and is not treated as a gap.
Composer is used for builds, but the repository reports no security-scanning tooling; this is a modest transparency and maintenance gap for an inactive package.
The repository is not archived, which is a compensating sign, but its last push was in April 2023 and does not offset the absence of recent commits.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
avangdev/avang-php-sendemail-api Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.