The repository still has two active contributors and four commits in the last three months, with tests and release notes. The license mismatch and 11 unpinned workflow actions reduce transparency and reproducibility.
44%
Total Score
100
38
50
Packagist marks the entire package abandoned, with no replacement provided; this is a strong adoption and maintenance warning even though the repository remains active.
The latest registry release was in July 2018, with no releases in roughly eight years. Recent repository activity partly offsets the stale registry publication record but does not remove the release risk.
The manifest declares a proprietary license while the repository license file is recognized as GPL-2.0. The repository is licensed, but the mismatch creates avoidable uncertainty for consumers.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap for a notification and email-handling plugin.
The audit completed cleanly with no untrusted checkouts, injection findings, or excessive permissions, but all 11 action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3 | — | — |
pelago/emogrifier Version ~1.0 | — | — |
sendgrid/sendgrid Version ^6.0 | — | — |
composer/installers Version ~1.0 | — | — |
mailgun/mailgun-php Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.