The MIT license, focused dependency set, clear README, and release notes make the package easy to evaluate. GitHub Actions use three unpinned references, leaving a modest build-reproducibility gap.
62%
Total Score
67
100
88
100
The package has 20 releases since September 2019, but none in the last 12 months and the latest registry release was in November 2023. This materially raises maintenance and abandonment concern.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful sign of currently inactive development and increases the risk that issues or compatibility changes will go unaddressed.
There were no new or closed issues or pull requests in the last month, despite seven open issues and six open pull requests. The lack of recent resolution activity is a maintenance concern.
Composer is used as the build tool, but no security scanning tool was detected. The missing scanner is a hygiene gap rather than evidence that the package is unsafe.
All three workflows were analyzed without audit failures or high-confidence findings, and none has top-level write permissions. However, all three action references are unpinned, which weakens build reproducibility.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-58303 fof/pretty-mail is vulnerable to Improper Neutralization of Special Elements Used in a Template Engine in versions 0.0.0 - 1.1.2. | 0.0.0 - 1.1.2 | High |
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^1.5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.