Security coverage is minimal, with no repository security policy or scanning tool. The tiny five-file package is clearly scoped, licensed under MIT, and has no install-time scripts, but it offers little evidence of ongoing care.
35%
Total Score
25
50
64
67
The last release was about 8 years and 10 months ago, with no releases in the last 12 months and only two releases overall. This is strong evidence of abandonment risk for a dependency.
There were no commits and no active maintainers in the last three months, consistent with the long gap since the last release. This materially increases abandonment risk.
The package has three runtime dependencies, including Symfony YAML and Swift Mailer, with no development dependencies. The dependency set is modest, but the absence of development dependencies offers little evidence of maintained testing or tooling.
The artifact and repository each contain only five files, including a Composer manifest and one source file. That is consistent with a very small package, but provides little evidence of broader project maturity.
The repository is owned by an individual user rather than an organization. That is normal for a small personal package, but it provides no additional backing to offset the lack of recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^3.3 | — | — |
swiftmailer/swiftmailer Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.