The repository is current, licensed, tested, and publishes release notes, with organizational backing. Seven of nine workflow actions are unpinned, and no security policy or scanning is reported.
82%
Total Score
100
100
94
50
Composer is used as the build tool, but no security-scanning tool is reported. This is a modest transparency gap rather than evidence of abandonment.
The repository has no documented security policy, reducing transparency for reporting and handling vulnerabilities; no provided signal compensates for that gap.
All three workflows were analyzed with no high-confidence audit findings or untrusted checkout and script-injection paths. However, seven of nine action references are unpinned, creating a real but limited workflow supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
horde/util Version ^3 || dev-FRAMEWORK_6_0 | — | — |
horde/exception Version ^3 || dev-FRAMEWORK_6_0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.