It includes tests, a changelog, a clear README, and a license. No security policy is published, and the workflow's action references are not pinned.
68%
Total Score
50
94
75
One contributor made all four recent commits, giving the project a top-contributor share of 100%. With user-owned project backing, this leaves maintenance dependent on a single person.
The repository had four commits in the last three months, showing recent activity, but all were produced by one active maintainer. The activity is positive but narrow.
No security policy is present. For an email-parsing library, the missing disclosure and response guidance is a real transparency gap, though it is not evidence of a security defect.
Version v0.2.4 is not a prerelease, but the package remains below 1.0, so API maturity and compatibility are less established than for a stable-major release.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, leaving dependency versions able to change unexpectedly.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pear/pear Version ^1.10 | — | — |
atk14/files Version ^1.6 | — | — |
atk14/translate Version ^1.2 | — | — |
yarri/utf8-cleaner Version ^1.1 | — | — |
atk14/string-buffer Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.