The release includes clear licensing, tests, a changelog, release notes, and no install-time scripts. Recent repository activity and organization backing help, but the workflow references are mostly unpinned and no security policy is provided.
68%
Total Score
67
100
94
75
All 3-month commit activity came from one contributor, giving the project a concentrated short-term bus factor. Organization backing provides some handoff capacity, so this is a maintenance caution rather than a severe risk.
Only 1 commit was recorded in the last 3 months, showing limited recent development activity. The recent release and push provide some compensation, but maintenance momentum is still thin.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanner reduces assurance about automated security checks without indicating abandonment.
The repository has no security policy. This weakens vulnerability-reporting transparency, although it does not by itself show that the package is unsafe.
Both workflows were analyzed with no high- or medium-confidence findings, no untrusted checkouts, and no script-injection sinks. However, 6 of 7 action references are unpinned, which leaves workflow dependencies exposed to moving upstream code; organization backing and the clean audit partly offset this hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
horde/exception Version ^3 || dev-FRAMEWORK_6_0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.