Package Health

horde/kolab_session

The package has a matching license, tests, and organizational backing, with no install-time scripts. Its registry history is stale and recent repository activity is absent; incomplete workflow pinning and no security policy add maintenance concerns.

Latest 2.0.3PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

Only two releases exist, both dating to December 2023, with no releases in the last 12 months. This weakens confidence that the published package is actively maintained.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. The non-archived repository and recent push metadata provide some context, but do not offset the lack of current commit activity.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, and no open work is visible. This is consistent with a quiet project and modestly increases abandonment risk.

Security policycaution

The repository has no documented security policy. That is a transparency and vulnerability-reporting gap, though it is not evidence of a security defect by itself.

Workflow auditcaution

All three workflows were analyzed without dangerous triggers, untrusted checkouts, or audit findings, but 5 of 8 action references are unpinned. The workflows are otherwise clean, so this is a limited reproducibility and supply-chain hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Gunnar Wrobel

Direct Dependencies

DependencyLast ReleaseScore
pear-pear.horde.org/horde_exception
Version >=2.0.0,<=3.0.0alpha1
—
—

Weekly Downloads

Info

Last Published
10 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform