Its documentation, tests, licensing, and security tooling are solid. CI needs cleanup because every action reference is unpinned and the release workflow contains high-confidence template-injection findings.
58%
Total Score
50
94
75
Although the package has six releases over about 20 months with a typical interval of about 27 days, it has had no releases in the last 12 months, which raises maintenance concerns.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the broader lack of releases and increasing abandonment risk.
No repository security policy was found, leaving vulnerability-reporting expectations unclear for a package that handles email credentials and messages.
All 22 analyzed action references are unpinned, and the release workflow has high-confidence template-injection findings plus archived actions. There are no untrusted checkouts or script-injection findings, so this is workflow hygiene risk rather than a severe standalone dependency verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
turahe/core Version ^1.0 | — | — |
ddeboer/imap Version ^1.19 | — | — |
turahe/media Version ^3.0 | — | — |
pelago/emogrifier Version ^7.2.0 | — | — |
zbateson/mail-mime-parser Version ^3.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.