The package is licensed, tested, and clearly tied to an organization-backed source repository. It lacks a security policy and automated security scanning, so maintenance confidence remains limited.
64%
Total Score
67
88
50
The package has five releases over roughly six years, with one release in the last 12 months and a latest release on September 21, 2025. The roughly nine-month median interval indicates slow but ongoing release activity.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, even though the recent release shows the project has not been abandoned outright.
There was recent issue and pull-request activity, including one new issue and two new pull requests in the last month, but none of those pull requests were merged. This suggests attention without demonstrated follow-through.
Composer is used for builds, but no security scanning tools were detected. The build process is defined, while security assurance is limited.
The repository has no security policy. For a server-integrated plugin handling groupware data, this reduces transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lolli42/finediff Version ~1.0.3 | — | — |
caxy/php-htmldiff Version ~0.1 | — | — |
pear/http_request2 Version ~2.5.0 | — | — |
kolab/libcalendaring Version >=3.4.0 | — | — |
roundcube/plugin-installer Version >=0.1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.