The package includes a usable README, an MIT declaration, and release notes for this version. Its small project has no recent activity or security scanning, so pinning this release warrants caution.
58%
Total Score
50
100
75
67
There were zero commits and zero active maintainers in the last 3 months. Combined with the old last push, this is meaningful evidence of stalled maintenance.
The latest release was about 2 years and 6 months ago, and there were no releases in the last 12 months. This indicates a largely inactive release cycle for a young package.
Composer build tooling is present, but no security scanning tools were detected. That weakens the project's ongoing security hygiene without making the release unfit on its own.
The linked repository is not archived, although its last push was about 2 years and 6 months ago. The active repository status is positive, but the age of the last push supports the maintenance concern.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a transparency gap for a client that handles mail-service integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.