Documentation, licensing, and package structure are clear, and the organization-backed repository matches the package. The release history is old and recent activity comes from only one contributor, so future maintenance is uncertain.
62%
Total Score
67
100
88
75
The package has nine releases but none in the last 12 months, with the latest release on January 30, 2018; this is a substantial maintenance concern despite the long publication history.
All recent commits came from one contributor, creating a concentrated maintenance dependency; organization backing provides some ability to hand work off but does not show that a second contributor is active.
There was one commit in the last three months from one active maintainer; this shows some activity but provides weak evidence of sustained maintenance.
Composer is used for builds, but no security-scanning tooling is present. This is a modest transparency and maintenance gap rather than a standalone severe risk.
The repository has no security policy, leaving vulnerability-reporting expectations unspecified.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drewm/mailchimp-api Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.