Documentation, tests, and licensing are in place, while one maintainer and no security policy limit transparency. The package has a focused dependency set and no install-time scripts.
62%
Total Score
50
88
75
The repository is owned by an individual account rather than an organization, so the single registry maintainer represents a relatively thin visible support base.
The package is effectively new, with three releases published within hours and no longer-term release history to demonstrate sustained maintenance.
The repository has zero commits and zero active maintainers in the past three months; because the project is newly published, this shows no maintenance track record rather than a confirmed long-term decline.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so there is no documented channel or process for reporting vulnerabilities in a package handling mail credentials and API access.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/mail Version ^8.0 | — | — |
guzzlehttp/guzzle Version ^6.3|^7.0 | — | — |
illuminate/support Version ^8.0 | — | — |
swiftmailer/swiftmailer Version ^6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.