Usable with caveats: it has a clear license, complete package documentation, tests, and a matching organization-backed repository. However, release history is sparse and the repository shows no commits or active maintainers in the last three months, so ongoing maintenance is uncertain.
67%
Total Score
67
100
83
80
Only two releases are recorded over roughly five and a half years, with a median interval of about five years and two months. The recent release is positive, but the overall cadence remains sparse and makes sustained maintenance harder to establish.
The repository recorded zero commits and zero active maintainers over the last three months. Combined with the very sparse release history, this is a meaningful warning about current maintenance capacity.
There is one new issue in the last month and no closed issues or merged pull requests, showing some user activity but no evidence of a responsive resolution workflow.
The repository has only one star, three forks, and five watchers, indicating limited external adoption. Popularity is supporting evidence rather than a verdict, so this modest reach is a caution but not a severe risk.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a transparency and process gap, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
horde/horde Version ^6 || dev-FRAMEWORK_6_0 | — | — |
horde/horde-installer-plugin Version dev-FRAMEWORK_6_0 || ^3 || ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.