The source project remains active, with 20 releases in the past year, tests, and a clear MIT license. Maintenance is concentrated in one recent contributor, and its workflow uses an unpinned container image.
45%
Total Score
67
75
67
Packagist marks the entire package as abandoned and names acdh-oeaw/arche-core as its replacement. This is a major adoption concern despite the package having recent releases.
One contributor made all commits in the last 3 months. Organization ownership provides some handoff capacity, but no second active contributor is shown to reduce concentration risk.
Only one commit was recorded in the last 3 months. Recent release activity offsets this somewhat, but the low commit activity still suggests limited ongoing maintenance capacity.
The repository is named arche-core rather than acdh-repo and its README does not mention acdh-repo. This creates uncertainty about whether the linked source repository directly corresponds to the published package.
The project uses Composer, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zozlak/auth Version ^3.1 | — | — |
zozlak/logging Version ^1 | — | — |
guzzlehttp/guzzle Version ^7 | — | — |
zozlak/http-accept Version >=0.1.0 <1 | — | — |
acdh-oeaw/arche-lib Version ^7.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.