Package Health

jfoucher/mailocal

The artifact includes tests, documentation, and an MIT license. Install-time scripts and absent security scanning reduce transparency, but these do not offset the maintenance concerns.

Latest v0.5.5PackagistPackagist

12%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

42

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption risk because the registry itself indicates the package should no longer be depended on.

Release historydanger

The latest release was over 6 years ago, with no releases in the last 12 months. This strongly indicates the package is no longer maintained for current environments.

Repo commit activitydanger

There were 0 commits and 0 active maintainers in the last 3 months. Combined with the archived repository, this shows no current maintenance capacity.

Repository archiveddanger

The linked repository is archived, confirming that active development has ended. Its last push was over 3 years ago, which materially increases abandonment and compatibility risk.

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts. These add installation complexity and supply-chain exposure, although the signal does not show that the scripts are malicious.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
react/socket
Version ^1.2
—
—
symfony/flex
Version ^1.1
—
—
symfony/form
Version 4.2.*
—
—
symfony/yaml
Version 4.2.*
—
—
symfony/asset
Version 4.2.*
—
—

Weekly Downloads

Info

Last Published
6 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform