Package Health

ernestdefoe/digest-mail

Healthy and reasonable to adopt, with some project-hygiene caveats. It has frequent recent releases, active work from two contributors, and a matching repository, but lacks tests, a changelog, security scanning, and a security policy.

Latest 2.2.2PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Maintainerscaution

Two registry maintainers are listed. The linked repository is owned by the same individual rather than an organization, so the small publishing base provides only modest redundancy.

Package scaffoldingcaution

The package includes a substantial README and the repository uses GitHub Releases, but neither the artifact nor repository contains tests or a changelog. That weakens maintenance transparency for a package with server-side email and database behavior.

Project backingcaution

The registry namespace and repository owner match, but the owner is an individual rather than an organization. This supports package identity while offering less institutional continuity.

Repo issue activitycaution

One issue was opened in the last month and none were closed, with no pull requests recorded. This is a small unresolved maintenance signal, though the project is only 96 days old.

Repo popularitycaution

The repository has zero stars, forks, and watchers. This is limited adoption evidence, but popularity alone does not outweigh the observed recent development.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ernestdefoe
Resofire

Direct Dependencies

DependencyLast ReleaseScore
flarum/core
Version ^2.0

Weekly Downloads

Info

Last Published
10 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform