Recent releases and ongoing repository work reduce abandonment concerns. The limited security documentation and weak workflow pinning leave modest transparency and build-hygiene gaps.
82%
Total Score
100
90
50
The repository name does not match the Packagist package name and its README does not mention the package. This creates some uncertainty about whether the linked repository directly represents the published package.
The linked repository has no security policy. For a plugin that stores outgoing mail and attachments, this is a transparency gap, although active maintenance and organizational backing partly offset it.
All 9 analyzed action references are unpinned, and the audit found a high-confidence low-severity adhoc package installation. The workflows had no untrusted checkout or script-injection findings, but reproducibility and build hygiene are weaker than they could be.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
shopware/core Version ~6.6.0 || ~6.7.0 | — | — |
zbateson/mail-mime-parser Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.