Documentation, tests, licensing, and a recent release make the package easy to evaluate. Its small dependency set and organization ownership help, while security scanning is absent.
72%
Total Score
83
100
94
75
All three recent commits came from one contributor, giving the project a thin current contributor base; organization backing partly compensates but does not remove the continuity risk.
Composer build tooling is used, but no security scanning tools were detected, leaving a maintenance and vulnerability-monitoring gap.
The repository has no security policy, which reduces transparency about reporting and handling security issues.
Both workflows were analyzed successfully with no high-confidence audit findings and one workflow scopes permissions at job level. However, six of seven action references are unpinned, creating a workflow supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
horde/cli Version ^3 || dev-FRAMEWORK_6_0 | — | — |
horde/util Version ^3 || dev-FRAMEWORK_6_0 | — | — |
horde/exception Version ^3 || dev-FRAMEWORK_6_0 | — | — |
horde/translation Version ^3 || dev-FRAMEWORK_6_0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.