The release has tests, a changelog, release notes, and a matching license. Repository security documentation is absent, while organization ownership provides some continuity.
68%
Total Score
67
93
67
One contributor made all recent commits, creating a concentrated maintenance dependency. Organization ownership offers some continuity, but no second recently active contributor is shown.
Only three commits were made in the last three months by one active maintainer. This shows recent maintenance but indicates limited current capacity.
Composer build tooling is present, but no security scanning tools are reported. That weakens transparency around automated security checks without indicating abandonment by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, not evidence that the release is unsafe.
The workflows have no dangerous triggers or audit findings, and one scopes permissions at job level. However, six of seven action references are unpinned, reducing build reproducibility and supply-chain control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
horde/support Version ^3 || dev-FRAMEWORK_6_0 | — | — |
horde/exception Version ^3 || dev-FRAMEWORK_6_0 | — | — |
horde/horde-installer-plugin Version dev-FRAMEWORK_6_0 || ^3 || ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.