Workflow dependencies are unpinned, and the repository has no security policy or automated security scanning. The project remains licensed, tested, correctly linked, and not archived.
52%
Total Score
50
75
50
The latest release was over three years ago, with no releases in the last 12 months; the earlier 91-release history shows prior activity but does not offset the current gap.
The repository recorded no commits and no active maintainers in the last three months, reinforcing the risk that maintenance has stopped.
Composer build tooling is present, but no security scanning tools were detected, limiting automated coverage for a framework package.
The repository has no security policy, so vulnerability reporting and disclosure expectations are unclear; repo_tooling also reports no security scanning tools.
The only workflow was fully analyzed with no dangerous audit findings, but all 3 of its action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpmailer/phpmailer Version ^6.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.