Package Health

phpdot/mail

phpdot/mail appears usable and reasonably transparent, with an MIT license, a coherent package and repository file layout, repository-level unit and integration tests, recent repository activity, and organization ownership. However, it is a young v0.x package only 53 days old with three releases, all recent commits come from one contributor, and the repository has neither security scanning nor a published security policy. These are meaningful maturity and maintenance-resilience concerns, but the active repository, organization backing, matching package repository, and testing evidence keep the release in the caution rather than unhealthy range.

Latest v0.3.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Release historycaution

The package is only 53 days old with three releases and a median release interval of about 27 days. This is active early development, but it provides limited evidence of long-term maintenance and maturity.

Repo bus factorcaution

One contributor made all three commits in the measured period, creating a concentrated maintenance dependency. Organization ownership provides some potential for handoff, but no second active contributor is shown.

Repo commit activitycaution

There were three commits in the last three months and the repository was updated recently, indicating ongoing activity, though the volume is modest for establishing durable maintenance.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools are configured. The missing scanning reduces supply-chain assurance, although it is not by itself evidence of an unsafe release.

Security policycaution

The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Omar Hamdan

Direct Dependencies

DependencyLast ReleaseScore
symfony/mime
Version ^8.0
symfony/mailer
Version ^8.0

Weekly Downloads

Info

Last Published
9 days ago
Created
2 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform