This is a healthy, mature release with a long history, seven releases in the last 12 months, a stable non-prerelease version, active recent commits and issue/PR handling, a substantial test suite, changelog, README, and a matching repository. It has no registry deprecation, is not archived, uses no install-time lifecycle scripts, and has a clear MIT license. The main concerns are that all recent commits came from one contributor, the runtime dependency surface is relatively broad, the repository lacks a security policy, and six publishing workflows grant top-level write permissions; these warrant review of the release and CI process but do not outweigh the package's strong maintenance and transparency signals.
82%
Total Score
70
50
94
80
The package has 27 runtime dependencies, including several Symfony, Doctrine, and extension requirements; this is a meaningful integration and transitive-maintenance burden, although it is coherent with the documented Symfony email-bundle scope.
Only one registry publishing maintainer is listed. This is a modest publishing continuity concern, though the repository shows active recent maintenance that partly compensates for it.
The repository is owned by a user account rather than an organization, so there is no provided organizational backing to offset the single-contributor bus-factor concern.
Recent activity is concentrated in one contributor, with one contributor making all 10 commits and holding 100% of the recent share; this creates continuity risk despite the repository's current activity.
The repository uses Composer build tooling, but no security-scanning tools were detected. The absence of scanning is a transparency and preventive-hygiene gap, not evidence of a defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.14 | — | — |
ramsey/uuid Version ^4.7 | — | — |
doctrine/orm Version ^3.6 | — | — |
symfony/lock Version ^7.4 | — | — |
symfony/mime Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.