The tiny three-file artifact is MIT-licensed and has no install scripts, keeping adoption simple. It lacks tests, a readme, a security policy, and security scanning, limiting maintenance transparency.
60%
Total Score
50
100
78
67
One registry account has publish access. That is a narrow publishing base, but the repository is also linked to the same net-tools owner, so this is a modest rather than severe concern.
The artifact and repository contain only LICENSE, composer.json, and one source file, with matching trees. This is transparent and simple, though it also confirms the project has very little supporting documentation or validation code.
The artifact has no readme, tests, or changelog, and the repository also has no tests or changelog. The absence of tests and changelog is normal packaging practice, but the missing readme reduces guidance for a library consumers must integrate.
The repository owner is the same net-tools namespace used by the package, but it is an individual account rather than an organization. This provides ownership continuity without strong evidence of broader project backing.
The package has had no releases in the last 12 months, despite nine releases since March 2024; this indicates a meaningful slowdown in maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient Version ^2.15.0 | — | — |
net-tools/mailing Version ^1.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.