The package has strong documentation, tests, release notes, and clear organizational ownership. Recent repository commits and issue handling are inactive, so future fixes may arrive slowly.
68%
Total Score
67
100
50
The package declares a post-autoload-dump lifecycle script, so installation can execute package-defined code. This is a supply-chain review consideration, but the signal alone does not show harmful behavior or make the release unfit.
The repository recorded 0 commits and 0 active maintainers in the last three months, which is a meaningful maintenance concern. The recent registry releases and repository push provide some evidence of ongoing ownership, but not of current development activity.
There were no new or closed issues and no merged pull requests in the last month, while 5 issues and 5 pull requests remain open. This supports the concern that maintenance and response may be slow.
The repository has no security policy file, leaving vulnerability-reporting guidance undocumented. This is a transparency gap, but it is not severe enough to outweigh the package's documentation, tests, and organizational backing.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 | — | — |
in2code/powermail Version ^13.0 || dev-eap | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.