The package is licensed, documented, and has a matching organization-owned repository with release notes. Its runtime dependency set and absent security policy add modest maintenance overhead.
58%
Total Score
100
50
81
83
The package has had no registry releases in the last 12 months, and its latest release was published over six years ago. Its five-release history and previously regular 27-day median interval provide some maturity, but do not offset the prolonged inactivity.
The package declares four runtime dependencies, including mailing and database components, creating meaningful transitive maintenance exposure. No development dependencies are declared, but that does not reduce runtime dependency risk.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are present. The missing scanning is a hygiene concern rather than a severe risk.
The linked repository has no security policy. This is a modest transparency gap for a form package that handles submissions, even though it is not evidence of a security defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wixel/gump Version 1.5.7 | — | — |
catfan/medoo Version 1.4 | — | — |
phpmailer/phpmailer Version 6.0 | — | — |
resknow/boilerplate Version ^4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.