The project includes tests, a changelog, release notes, and a matching repository. Its very recent history, zero three-month commit activity, absent security policy, and fully unpinned workflow actions leave meaningful adoption risk.
58%
Total Score
50
80
67
The package is 0 days old with four releases published within hours, so there is not yet evidence of sustained maintenance or a settled release process.
The repository reports zero commits and zero active maintainers in the last three months; because the project is newly published, this is partly explained by its age but still provides no established maintenance evidence.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a package that handles mailbox credentials and email data.
Version v0.2.1 is not a stable major release, indicating an early API and behavior stage despite not being marked prerelease.
All 12 workflow action references are unpinned, which weakens build reproducibility; the workflow is otherwise fully analyzed, uses read-only permissions, and has no detected high-confidence dangerous findings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
laravel/framework Version ^12.40|^13.0 | — | — |
symfony/html-sanitizer Version ^7.1|^8.0 | — | — |
directorytree/imapengine Version ^1.25 | — | — |
zbateson/mail-mime-parser Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.