Healthy and usable, with some early-project risk. It has active recent work, strong documentation and tests, a clear license, and organization backing; the main caveat is that all recent commits come from one contributor and the project is only 51 days old.
78%
Total Score
67
100
81
90
The package is very young at 51 days and has only two releases, so its long-term maintenance record is not yet established. This is an early-maturity caveat rather than evidence of abandonment because repository activity is recent.
One contributor made all 10 commits in the last three months, creating a low bus factor. Organization backing partly compensates because maintenance can potentially be handed off, but no second active contributor is evidenced.
The repository recorded 10 commits in the last three months, showing active development. However, all activity is concentrated in one maintainer, which limits resilience if that person stops contributing.
Composer build tooling is present, but no security-scanning tool was detected. The build setup is adequate, while the lack of automated security scanning is a modest transparency and assurance gap.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a modest transparency gap for a package that handles API credentials and email-platform integrations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.