The Apache-2.0 license and focused README make installation and basic use understandable. There are no security-scanning tools or security policy, leaving limited evidence of ongoing project safeguards.
42%
Total Score
50
70
75
The package has had no releases in the last 12 months, and its latest release was about 2 years and 5 months ago. Seven releases in the initial period show it was published, but do not offset the prolonged silence.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the release gap and raising abandonment risk.
The repository has 0 stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no additional evidence of community review or adoption.
Composer build tooling is present, but no security-scanning tools were detected. That leaves a meaningful project-hygiene gap for a package handling email and attachments.
The repository has no security policy, so users have no documented reporting path or stated security process. This is a transparency weakness, though it is not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ddeboer/imap Version ^1.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.