Maintenance has recently slowed, with no commits or active maintainers in the last three months. The missing security policy and unpinned workflow actions add modest transparency and build-integrity concerns, although the repository is active, tested, licensed, and not deprecated.
68%
Total Score
75
100
88
67
The package has nine releases since August 2022 and a release on June 3, 2026, but only one release in the last 12 months. This supports continued maintenance while indicating a slower recent cadence.
The repository recorded zero commits and zero active maintainers in the last three months. That is a real maintenance concern, though the recent release and non-archived status provide some compensation.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning coverage is a modest repository hygiene gap, not evidence that the package is unsafe.
The repository has no documented security policy. This weakens vulnerability-reporting transparency for a package that handles mail transport configuration.
The single workflow was fully analyzed with no high- or medium-confidence findings, no untrusted checkout, and no script injection. However, both action references are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/mailer Version ^6.0|^7.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
mailchimp/transactional Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.