The package has only four releases across about six years and no commits in the last three months. It has a clear MIT license, a matching organization-owned repository, and a current stable release, but no tests or security policy add little assurance.
62%
Total Score
75
100
83
83
Only four releases have appeared since August 2020, with a median interval of about 667 days, although two releases arrived in the last 12 months. This indicates intermittent rather than consistently active maintenance.
There were no commits and no active maintainers in the last three months. Combined with the sparse release history, this weakens evidence of ongoing maintenance.
The repository has zero stars and forks and one watcher. Low popularity is only supporting evidence, but it provides little independent evidence of maturity or community support.
The repository uses Composer, appropriate for this package, but no security scanning tooling is present. This is a modest transparency and assurance gap.
No security policy was found in the repository, leaving vulnerability-reporting expectations and response information unspecified.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.8.2 | — | — |
devorto/mail Version ^4.0.0 | — | — |
kriswallsmith/buzz Version ^1.3.0 | — | — |
mailgun/mailgun-php Version ^4.3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.