Its last release was over ten years ago, and it carries 33 runtime dependencies. The package has only one registry maintainer and no recent releases, leaving adoption and ongoing support highly uncertain.
8%
Total Score
50
50
33
Packagist marks the entire package as abandoned, with no replacement package specified. Package-level deprecation is a severe dependency risk.
The latest release was published over ten years ago, with no releases in the last 12 months. This is strong evidence of abandonment despite the package having 32 historical releases.
The package declares 33 runtime dependencies and no development dependencies. This creates a broad, difficult-to-maintain dependency surface for an abandoned package.
Only one account has registry publish access. This is a limited maintenance base, although registry access alone does not prove who actively maintains the code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hoa/mime Version 3.* | — | — |
baum/baum Version 1.* | — | — |
curl/curl Version 1.* | — | — |
nette/mail Version 2.* | — | — |
keboola/csv Version 1.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.