Its organization ownership gives maintenance some resilience, while the workflow audit found no risky patterns. The small public footprint and absent security policy are modest transparency concerns.
88%
Total Score
100
100
89
75
The repository has only 2 stars and 10 forks, indicating a small public footprint, but popularity is supporting evidence and does not outweigh the active maintenance signals.
Composer is used for builds, but no security scanning tool was detected, leaving a modest repository hygiene gap.
The repository has no security policy, which makes vulnerability-reporting expectations less transparent for a security-sensitive web application.
Both workflows were analyzed with no failed files, risky triggers, injection findings, or audit findings. Four of six action references are unpinned, a minority and therefore a minor reproducibility concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
horde/url Version ^3 || dev-FRAMEWORK_6_0 | — | — |
horde/vfs Version ^3 || dev-FRAMEWORK_6_0 | — | — |
horde/auth Version ^3 || dev-FRAMEWORK_6_0 | — | — |
horde/core Version ^3 || dev-FRAMEWORK_6_0 | — | — |
horde/mime Version ^3 || dev-FRAMEWORK_6_0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.