Clear licensing, useful documentation, and organization backing make the project easier to adopt. The workflow audit found no dangerous patterns, though several action references are not pinned and repository activity evidence is thin.
58%
Total Score
67
100
85
83
The package has had no release in the last 12 months despite being 494 days old, which weakens confidence that this release is actively maintained. Its three releases were initially spaced about 11 days apart, providing some early release history.
There were zero commits and zero active maintainers in the last three months, a strong sign of thin current maintenance capacity. This conflicts somewhat with the recent repository push timestamp, so it is serious caution rather than abandonment by itself.
One issue was opened in the last month and none were closed, showing some user activity but no demonstrated issue resolution during that period.
The repository has only 1 star and 2 forks, indicating limited public adoption. Popularity is supporting evidence rather than a decisive health measure, so this is a modest concern.
The repository uses Composer, which fits the package ecosystem, but no security scanning tools were detected. The missing scanning is a maintenance hygiene gap, not evidence that the release is unsafe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
horde/vcs Version ^1 || dev-FRAMEWORK_6_0 | — | — |
horde/horde Version ^6 || dev-FRAMEWORK_6_0 | — | — |
horde/horde-installer-plugin Version dev-FRAMEWORK_6_0 || ^3 || ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.