Risky to adopt: the package has had no release or repository activity since December 2018, leaving maintenance and compatibility uncertain. It is not deprecated or archived and has a clear, licensed, small package, but the long inactivity is a substantial liability.
42%
Total Score
50
100
78
83
The latest release was in December 2018, with no releases in the last 12 months. A package that has gone about 7 years and 9 months without a release has a substantial abandonment and compatibility risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap. This is the strongest evidence that ongoing maintenance is unavailable.
The repository has zero stars and forks and only two watchers. Popularity is supporting evidence rather than a verdict, but these numbers provide little external evidence of active community support.
Composer is used as the build tool, which is appropriate for a Packagist PHP package, but no security scanning tools are configured. The missing scanning is a minor supply-chain hygiene concern.
The repository has no security policy. This is a transparency gap for reporting vulnerabilities, although the package has no recent activity and no other provided signal compensates for it.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mailgun/mailgun-php Version ~2.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.