The release is licensed and includes documentation, tests, and a full source tree. Its workflow has no high-risk audit findings, but unpinned actions add avoidable maintenance risk.
12%
Total Score
0
100
40
75
The registry marks the entire package as abandoned, not merely this release, and provides no replacement. That is a severe warning for ongoing maintenance and dependency adoption.
The package has a long history with 115 releases, but none in the last 12 months. Its historical maturity does not compensate for the current release pause alongside abandonment and archival signals.
The repository recorded zero commits and zero active maintainers in the last three months, providing no evidence of current development capacity.
The linked source repository is archived, which indicates the project is no longer intended for active maintenance even though it was pushed recently.
The linked repository has no security policy, leaving vulnerability-reporting expectations and disclosure guidance unspecified. This is a transparency gap for a framework package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
swiftmailer/swiftmailer Version >=5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.