It includes tests, a matching MIT license, and no install-time scripts. Its five releases in 15 days show activity, but the replacement package is the maintained path.
18%
Total Score
71
75
Packagist marks the entire package as abandoned and names symfony/puffer-post-mailer as its replacement. This is a decisive adoption risk even though the repository remains available.
The package is only 15 days old but already has five releases, including activity on the assessed date. That shows short-term activity, but not an established maintenance record.
The repository has no security policy. That is a transparency gap, although it is secondary to the package's explicit replacement.
Version v0.1.4 is not a stable major release, so its API and maintenance direction are less established. The explicit replacement further reduces confidence in building on this line.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
pufferpost/sdk Version ^0.1 | — | — |
symfony/config Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/mailer Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/http-kernel Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/dependency-injection Version ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.