Healthy and suitable to use, with a small maintenance caveat. It has a long release history, a current non-archived repository, clear licensing, tests and release notes in the source project, but recent work is limited to one active contributor and few commits.
78%
Total Score
63
100
94
100
All three commits in the last three months came from one contributor, giving the release a narrow recent contributor base. Because the repository is owned by an organization, handoff is possible, but no second active contributor is shown by this signal.
The repository recorded three commits in the last three months, showing recent work but a low maintenance tempo. This is consistent with a mature, slower-moving library rather than strong ongoing development.
The repository has 51 open issues and 44 open pull requests, with one issue opened and one closed in the last month; one pull request was opened but none were merged. The project is still receiving activity, but the backlog and lack of recent merges are a maintenance caution.
Composer is used for builds, which supports reproducible project management, but no security scanning tools were detected. The missing scanning is a transparency and maintenance gap, though it is not by itself evidence that the package is unsafe.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-54119 adodb/adodb-php is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 5.22.9. | 0.0.0 - 5.22.9 | Critical |
CVE-2025-46337 adodb/adodb-php is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 5.22.8. | 0.0.0 - 5.22.8 | Critical |
CVE-2016-4855 adodb/adodb-php is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 5.20.6. | 0.0.0 - 5.20.6 | Medium |
CVE-2016-7405 adodb/adodb-php is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 5.0 - 5.20.7. | 5.0 - 5.20.7 | Critical |
CVE-2021-3850 adodb/adodb-php is vulnerable to Improper Authentication in versions 0.0.0 - 5.20.20 and 5.21.0 - 5.21.3. | 0.0.0 - 5.20.205.21.0 - 5.21.3 | Critical |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.