The package is clearly licensed, documented, and tied to a matching source repository. However, the repository has had no commits or issue activity for about 17 months, and no security policy is present.
64%
Total Score
67
100
89
75
This is a mature package with 83 releases since January 2017 and a median release interval of about 10 days, but it has had no registry release in the last 12 months. The long release history partly compensates for the recent pause.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with roughly 17 months since the last push. This is the strongest concern because it limits evidence of ongoing maintenance.
There were no new or closed issues and no merged pull requests in the last month, with 12 issues still open. This indicates little recent project activity, though the backlog is not large enough to imply abandonment alone.
Composer is used for the build, showing basic project tooling, but no security scanning tools are configured. The missing scanning is a hygiene gap rather than evidence that the release is unsafe to depend on.
The repository has no security policy. For a library handling email credentials and messages, this reduces transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
webklex/php-imap Version ^6.2.0 | — | — |
laravel/framework Version >=6.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.