Clear documentation, extensive tests, and an MIT license make the package easier to adopt. The organization-backed repository is not archived, but security review and workflow hygiene remain limited.
58%
Total Score
75
92
67
This is the package's only release, published 400 days ago, with no releases in the last 12 months. That limited history and long silence raise maintenance risk, though the project is still relatively young.
The repository had 0 commits and 0 active maintainers in the last 3 months. With only one release, this provides little evidence of ongoing maintenance.
The repository has no security policy or documented reporting path. This is a transparency gap for a mail-sending library, although it does not by itself show an active security problem.
All 8 action references are unpinned, and the workflow uses a floating container image tagged latest; the high-confidence unpinned-image finding weakens build reproducibility. The audit was complete and found no untrusted checkout or script injection.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3 | — | — |
symfony/mime Version ^6.0 || ^7.0 | — | — |
symfony/mailer Version ^6.0 || ^7.0 | — | — |
twig/extra-bundle Version ^3.4 | — | — |
symfony/twig-bridge Version ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.