Package Health

nettsite/nettmail-laravel

NettMail Laravel package - Eloquent models, service provider, queued jobs, and Livewire admin UI for the NettMail core package

Latest v0.2.4PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Dangerous workflowscaution

One workflow uses pull_request_target for Dependabot auto-merge. No untrusted checkout or script injection was detected, but this workflow type warrants extra review because it runs with elevated repository context.

Lifecycle scriptscaution

The package runs a post-autoload-dump install-time script. This is not inherently unsafe, but install-time execution adds operational risk compared with a package with no lifecycle scripts.

Release historycaution

There are six releases, but they were concentrated within roughly two days and the latest release was about three months ago, giving limited evidence of sustained release maintenance.

Repo commit activitycaution

The repository recorded only two commits in the last three months, although two maintainers contributed equally; this suggests limited recent development rather than a single-maintainer bottleneck.

Repo issue activitycaution

There are two open pull requests, one new in the last month, but none merged and no issue activity in that period, providing weak evidence of ongoing project responsiveness.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Nettsite

Direct Dependencies

DependencyLast ReleaseScore
webklex/php-imap
Version ^6.0
—
—
guzzlehttp/guzzle
Version ^7.8
—
—
livewire/livewire
Version ^4.3
—
—
illuminate/database
Version ^11.0||^12.0||^13.0
—
—
illuminate/contracts
Version ^11.0||^12.0||^13.0
—
—

Weekly Downloads

Info

Last Published
3 months ago
Created
4 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform