The package has clear documentation, tests, a changelog, and a matching source repository. Its BSD-3-Clause licensing and lack of install scripts reduce adoption friction, but no security policy or scanning leaves transparency weaker.
38%
Total Score
50
72
75
This is the package's only release, published about 11 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk for a library handling third-party mail services.
Only one registry maintainer is listed. For this user-owned project, that leaves little visible publishing redundancy and increases continuity risk if the maintainer stops supporting it.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no community signal to offset the stale release history.
Composer is used for builds, but no security-scanning tools are present. That weakens supply-chain transparency, especially for a package that integrates with external services.
The repository has no security policy. This makes vulnerability reporting and maintenance expectations less transparent, though it is not evidence of a vulnerability by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zendframework/zend-http Version ~2.0 | — | — |
zendframework/zend-mail Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.