The package has a stable major release, matching source repository, license, tests, and release notes. Organization backing and a security policy support continued ownership, but its sparse release history leaves maintenance less proven.
61%
Total Score
75
93
100
Only 3 releases have been published since October 2020, with no releases in the last 12 months and a median interval of about 865 days. The July 2025 release is recent enough to avoid an abandonment verdict, but the cadence is sparse.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. This is meaningful maintenance uncertainty, even though the repository was pushed recently and the latest release supports PHP 8.1–8.4.
All 13 analyzed action references are unpinned, and a high-confidence audit found an unpinned container image in the test workflow. Both weaken build reproducibility, though there are no untrusted checkouts, script-injection findings, or broad top-level write permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpmailer/phpmailer Version ^6.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.