The release includes tests, a changelog, release notes, and a recent publishing cadence. Its declared BSD-2-Clause license differs from the BSD-3-Clause file, and eight of ten workflow actions are unpinned. Recent repository work is concentrated in one contributor, so continuity depends on a narrow maintainer base.
68%
Total Score
67
100
81
67
The package declares BSD-2-Clause, while its artifact license file is detected as BSD-3-Clause; although a license is present, the mismatch creates avoidable legal uncertainty.
One contributor made 100% of the four commits in the last three months. Organization backing provides some handoff capacity, but the observed recent maintenance base remains concentrated.
The repository recorded 4 commits in the last three months, showing recent activity, but only one active maintainer contributed them. The activity is real but narrow.
Composer build tooling is present, but no security-scanning tool was detected. The missing scan is a maintenance and assurance gap, not evidence of malicious behavior.
The repository has no security policy. For an application package, this weakens vulnerability-reporting transparency and incident-response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
horde/db Version ^3 || dev-FRAMEWORK_6_0 | — | — |
horde/core Version ^3 || dev-FRAMEWORK_6_0 | — | — |
horde/horde Version ^6 || dev-FRAMEWORK_6_0 | — | — |
horde/routes Version ^3 || dev-FRAMEWORK_6_0 | — | — |
horde/horde-installer-plugin Version dev-FRAMEWORK_6_0 || ^3 || ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.