The package is clearly licensed, documented, tested, and has a small, focused dependency set. Its workflow is fully analyzed without dangerous findings, but it lacks security scanning and has only one registry maintainer.
62%
Total Score
67
100
88
75
Only one account has registry publish access. That is a thin operational base for a package handling application email, although the linked repository is owned by the same individual, so this is not an ownership mismatch.
There have been only two releases, both on October 7, 2025, with no release activity afterward despite the package being about 348 days old. This points to limited demonstrated maintenance capacity.
The repository recorded zero commits and zero active maintainers in the last three months, supporting the concern that maintenance has gone quiet. The repository is not archived, but that does not offset the absent recent activity.
Composer build tooling is present, but no security scanning tools were detected. That is a transparency and maintenance-hygiene gap, though it is not severe on its own.
The single workflow was fully analyzed with no dangerous audit findings, no untrusted checkout or script-injection paths, and no top-level write permissions. Both action references are unpinned, which is a modest reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/mailer Version ^6.0|^7.0 | — | — |
illuminate/mail Version ^10.0|^11.0|^12.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
maileroo/maileroo-php-sdk Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.