Package Health

spatie/craft-mailcoach

Its MIT licensing, organization backing, and release notes make the package easy to evaluate. Maintenance evidence is limited, with only one release and no commits in the last three months; workflow references also need tighter pinning.

Latest 1.0.0PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

This is the package's only release, published about 11 months ago, so there is little release history from which to judge sustained maintenance.

Repo commit activitycaution

The repository recorded no commits from active maintainers in the last three months, weakening evidence of ongoing maintenance.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations undocumented; this is a modest transparency gap for a dependency.

Workflow auditcaution

All seven analyzed action references are unpinned, which weakens build reproducibility. One workflow has a pull_request_target trigger and top-level write permissions, but the audit found no untrusted checkout or script-injection sink, so this remains a hygiene concern rather than a severe workflow risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
craftcms/cms
Version ^5.0.0
—
—
spatie/mailcoach-mailer
Version ^1.3.0
—
—

Weekly Downloads

Info

Last Published
12 months ago
Created
12 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform