Risky to adopt: the package has had no release or repository activity since May 2018, with only one star and no tests. It is small and clearly licensed, but its long abandonment and repository/package mismatch make ongoing support uncertain.
38%
Total Score
0
100
67
75
The latest release was in May 2018, and there have been no releases in the last 12 months despite the package being over 11 years old. This is strong evidence of abandonment for a dependency that may need compatibility or security fixes.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no updates for more than eight years. No provided activity signal compensates for this lack of maintenance.
The repository name does not match the assessed package name, and its README does not mention the package. This raises concern that the linked source may not clearly correspond to the published release.
The repository has one star, zero forks, and one watcher, providing little evidence of community use or external review. Low popularity alone is not decisive, but it offers no support against the long maintenance gap.
Composer is used as a build tool, but no security scanning tools are present. The absent scanning is a transparency and maintenance weakness, although the repository has no workflows or build automation that would add additional risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pelago/emogrifier Version @dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.