Package Health

pylesoft/mailbox

This is a promising but very young package with strong transparency and scaffolding: it has a substantial 239-file repository, tests, extensive documentation, a declared MIT license, no install-time lifecycle scripts, a matching source repository, and recent release activity. However, v0.1.3 is still pre-1.0, the project is only 96 days old, recent commit activity consists of just 2 commits from one contributor, and the repository lacks security scanning, a security policy, and explicit workflow token permissions. It is reasonable to evaluate for use with appropriate version pinning and operational review, but it does not yet demonstrate the maturity or maintainer redundancy of a low-risk dependency.

Latest v0.1.3PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dependency profilecaution

The package declares 11 runtime dependencies, including several Laravel components and Guzzle. This is a meaningful integration surface but is proportionate to a Laravel mailbox SDK and is not severe on its own.

Release historycaution

The package is only 96 days old with 4 releases and a median release interval of about 30 days. This shows ongoing publication but provides limited evidence of long-term maintenance.

Repo bus factorcaution

One contributor made all 2 commits in the last 3 months, giving the repository a 100% top-contributor share. Organization ownership offers some handoff potential, but no second active contributor is shown, so maintainer concentration remains a concern.

Repo commit activitycaution

Only 2 commits were recorded in the last 3 months, from one active maintainer. Recent publication and merged pull requests help, but the observed maintenance cadence is thin for a new integration-heavy package.

Repo popularitycaution

The repository has only 1 star, 0 forks, and 0 watchers. This weakens external adoption evidence, but popularity is supporting evidence and does not by itself indicate abandonment.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
illuminate/http
Version ^12.0||^13.0
—
—
laravel/prompts
Version ^0.3
—
—
illuminate/cache
Version ^12.0||^13.0
—
—
psr/http-message
Version ^2.0
—
—
guzzlehttp/guzzle
Version ^7.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
4 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform