The repository includes tests, release notes, a security policy, and Composer security scanning. GitHub Actions use read-only permissions but both referenced actions are unpinned, so reproducibility remains a modest concern.
72%
Total Score
50
88
83
Only two releases exist and the package is less than one day old, so there is not yet enough release history to establish mature maintenance or compatibility patterns.
No commits or active maintainers were recorded over the last three months, limiting evidence of sustained maintenance; the package's very recent creation makes this signal less conclusive.
The release is non-prerelease but remains on the 0.x major line, which signals an API that may still change substantially.
The single workflow was fully analyzed, uses read-only permissions, and has no high-confidence audit findings, but both action references are unpinned, leaving a modest reproducibility and action-integrity gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/mime Version ^6.4 || ^7.0 || ^8.0 | — | — |
egulias/email-validator Version ^4.0 | — | — |
zbateson/mail-mime-parser Version ^3.0.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.