Clear licensing, documentation, and a recent release provide useful transparency. The small project has no tests or security scanning, so pinning this pre-1.0 dependency deserves care.
69%
Total Score
75
78
75
The package includes a substantial README and a changelog, which help consumers understand and track it. No tests are published or present in the repository, a minor maintenance gap for a mail library.
There were no commits and no active maintainers in the three months before collection. The recent push and release history partly offset this, but the current development lull is a real maintenance concern.
The repository has zero stars, forks, and watchers, indicating little visible external adoption or review. Popularity is only supporting evidence, so this lowers confidence more than it determines the health verdict.
Composer build tooling is present, but no security-scanning tools are configured. For a package handling mail credentials and transport, that leaves a meaningful security-maintenance gap.
The repository has no security policy. This reduces transparency for reporting vulnerabilities in a package that handles SMTP configuration and message delivery.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
frootbox/config Version ^0.0.9 || ^1.0 | — | — |
phpmailer/phpmailer Version 6.6.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.