Usable with caveats: the package is licensed, documented, tested, backed by a matching organization repository, and not deprecated. However, its last registry release was over five years ago and there has been no recent commit activity, so compatibility and maintenance should be verified before adoption.
68%
Total Score
83
100
88
90
Although the package has 21 releases and a history since 2016, its latest registry release was on August 6, 2021, with no releases in the last 12 months; this is a meaningful freshness and maintenance concern.
The repository had no commits and no active maintainers in the three months before collection, reinforcing the concern that active maintenance has slowed or stopped.
Composer is used as a build tool, but no security scanning tooling is configured. This is a modest transparency and maintenance gap rather than a severe risk, given the repository's visible source and tests.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drewm/mailchimp-api Version 2.5.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.