This is a usable but immature release. The package is clearly licensed, non-deprecated, actively updated very recently, and backed by a repository whose contents match the artifact and whose recent commits are split across two contributors. However, it is only 25 days old, remains on the 0.x line, has no packaged or repository tests or changelog, and lacks both security-scanning tooling and a security policy. The small individual-maintainer project and zero repository popularity are not decisive by themselves, but the limited maturity and transparency mean developers should review the code and avoid treating it as a low-risk, established dependency.
64%
Total Score
75
100
75
83
Only one registry account has publish access. This is a modest continuity concern for an individual-owned project, although repository activity shows a second active contributor.
A substantial README is present, but neither the artifact nor repository contains tests or a changelog; no provided evidence compensates for these transparency and validation gaps.
The repository is owned by an individual rather than an organization, so there is no organizational maintenance backing to offset the project's limited history and single registry publisher.
The package is only 25 days old with three releases and a median interval of about 13 days, showing initial activity but insufficient history to establish mature stability.
Composer is used as a build tool, but no security-scanning tooling is reported; this weakens automated assurance for a plugin handling email content.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
roundcube/plugin-installer Version ~0.3.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.