The package includes tests, a substantial README, and release notes for this version. Its license records disagree, and the repository has no security policy, increasing uncertainty for long-term use.
42%
Total Score
25
70
75
The latest release was published in June 2017, with no releases in the following nine years. That long release gap is strong evidence of abandonment risk despite the package having ten releases overall.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the absence of recent registry releases and indicating little ongoing maintenance.
The manifest declares GPL-3.0, but the repository license file was detected as MIT. Although both indicate an intended license, the mismatch creates legal uncertainty for consumers.
There were no new or closed issues or pull requests in the last month, while three issues remain open. This supports the broader picture of an inactive project.
The repository has no security policy. This is a transparency gap for a library that implements an email server, where users may need a clear process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
thefox/logic Version ^1.0 | — | — |
thefox/network Version ^1.0 | — | — |
thefox/storage Version ^0.1 | — | — |
symfony/filesystem Version ^2.5 || ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.