Security documentation and automated security scanning are absent, which reduces transparency for a package handling incoming email. The release includes notes, a README, a matching repository, and no install-time scripts or deprecation notice.
68%
Total Score
63
100
78
75
The repository is owned by an individual user rather than an organization. Combined with the concentrated contributor activity, there is no visible organizational maintenance buffer.
The package has only four releases across about 4 years and 1 release in the last 12 months, with a median interval of about 13 months. The recent release shows the project is not abandoned, but the cadence is slow.
All recent commits come from one contributor, with a 100% top-contributor share. The user-owned project has no organizational backing shown to compensate for that concentration.
Only one commit was recorded in the last 3 months, showing limited recent development activity. This is evidence of a small maintenance effort, even though it does show some ongoing activity.
The repository has 2 stars, 0 forks, and 1 watcher, indicating a very small adoption footprint. Popularity is supporting evidence only, so this modestly limits external maintenance signals rather than determining the verdict.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.