The package includes tests, a changelog, release notes, and a clear license, with recent repository activity. Maintenance is concentrated in one contributor, and six of seven workflow actions are unpinned; organizational ownership reduces but does not remove those concerns.
68%
Total Score
75
100
88
67
This is the only release, published 83 days after the package's first release, so there is not yet enough history to establish a durable release cadence. Its recent publication limits the concern but does not remove the maturity gap.
One contributor made all three recent commits, concentrating maintenance in a single person. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository had three commits in the last three months, showing recent activity, but the volume is modest for establishing strong ongoing maintenance.
Composer build tooling is present, but no security scanning tool was detected. The missing scanner is a modest transparency and hygiene gap, not evidence of unsafe code.
The repository has no security policy. This weakens the documented process for handling vulnerabilities, though it is not by itself evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
horde/cli Version ^3 || dev-FRAMEWORK_6_0 | — | — |
horde/log Version ^3 || dev-FRAMEWORK_6_0 | — | — |
horde/util Version ^3 || dev-FRAMEWORK_6_0 | — | — |
horde/autoloader Version ^3 || dev-FRAMEWORK_6_0 | — | — |
horde/cli_modular Version ^3 || dev-FRAMEWORK_6_0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.