The package has a long release history, regular recent releases, an MIT license, tests, and organization backing. The linked repository does not mention the package and has no security policy, limiting transparency around ownership and security practices.
68%
Total Score
75
100
86
75
No commits and no active maintainers were recorded in the last three months. The recent package release and broader release cadence soften this, but the repository activity still signals limited recent development.
The repository name does not match the package name and its README does not mention enhavo/newsletter-bundle. Even if this is a subtree split, the package-to-source relationship is less transparent.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest security-process gap rather than evidence that the release is unsafe.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/lock Version ^6.4 | — | — |
enhavo/app-bundle Version ^0.15 | — | — |
enhavo/cleverreach Version ^0.15 | — | — |
enhavo/form-bundle Version ^0.15 | — | — |
enhavo/block-bundle Version ^0.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.