Its MIT licensing, stable versioning, and repository/package match add useful transparency. Dependence on one active contributor and a floating CI image leave modest maintenance and build-reproducibility concerns.
77%
Total Score
83
100
67
All 24 recent commits came from one contributor, leaving maintenance highly concentrated and creating a meaningful continuity risk.
The repository has no published security policy, which reduces transparency for reporting and handling vulnerabilities in an integration-focused library.
All three workflows were analyzed successfully and have no untrusted checkout or script-injection findings, but the audit found a high-confidence workflow using a floating latest container image, weakening build reproducibility.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10167 directorytree/imapengine is vulnerable to Command injection in versions 1.0.0 - 1.22.2. | 1.0.0 - 1.22.2 | High |
| Dependency | Last Release | Score |
|---|---|---|
symfony/mime Version >=6.0 | — | — |
nesbot/carbon Version >=2.0 | — | — |
illuminate/collections Version >=9.0 | — | — |
egulias/email-validator Version ^4.0 | — | — |
zbateson/mail-mime-parser Version ^3.0|^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.