The repository has no security policy, and all three workflow action references are unpinned. Licensing is clear and the source tree includes tests, but those positives do not offset the maintenance concerns.
12%
Total Score
0
63
50
Packagist marks the entire package as abandoned and recommends symfony/mailer as a replacement. Package-wide deprecation is a severe dependency risk, not merely a release-level warning.
The repository recorded zero commits and zero active maintainers over the past three months. This provides strong evidence that fixes and compatibility updates are unlikely.
All four releases occurred within the last 12 months, with a median interval of about 8 minutes, indicating a brief burst rather than an established maintenance cadence.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, although it is secondary to the package-wide deprecation.
All three analyzed workflows use unpinned action references, reducing build reproducibility and increasing exposure to action changes. No untrusted checkout, script injection, or high-severity audit finding was reported.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
webmozart/assert Version ^1.11.0 | — | — |
laminas/laminas-loader Version ^2.9.0 | — | — |
laminas/laminas-stdlib Version ^3.17.0 | — | — |
laminas/laminas-validator Version ^2.31.0 | — | — |
symfony/polyfill-intl-idn Version ^1.27.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.