The bundle is small, clearly licensed, and has a focused dependency profile with no install-time scripts. It lacks security scanning and a security policy, leaving little evidence of ongoing oversight.
32%
Total Score
33
100
75
75
The package has only three releases, all concentrated around March 2014, with no releases in the last 12 months and a package age of about 12.5 years. This is strong evidence of abandonment for a maintained integration package.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the last push in 2014, this indicates sustained abandonment.
The repository is owned by a personal user account rather than an organization. That does not prove the project is unsafe, but it provides no organizational maintenance backing to offset the inactivity.
There were no recent issues or pull requests, and none are currently open. This is consistent with an inactive project, though it provides less evidence than the release and commit history.
Composer is used as the build tool, but no security scanning tools are configured. The build setup is appropriate, while the missing security tooling is a modest transparency and oversight gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dcsg/mailchimp-api-connector Version ~2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.