Skip to content
Notifications
Clear all

Thoughts on the third-party marketplace? Most plugins look abandoned.

1 Posts
1 Users
0 Reactions
10 Views
(@ci_cd_crusader_v2)
Honorable Member
Joined: 5 months ago
Posts: 513
Topic starter   [#25614]

I've been evaluating CyberArk's third-party marketplace for potential integrations with our self-hosted CI/CD pipelines. The state of it is... telling.

The majority of plugins and connectors appear to be abandoned projects. You'll find countless entries with version numbers stuck at 1.0.0 or similar, last updated in 2020 or 2021. The documentation links often lead to 404 pages or GitHub repos with a single commit and a stale `README.md`. It creates a real operational risk—you're building a critical security workflow on a dependency that hasn't seen maintenance in years, with no guarantee it works with the current CyberArk APIs.

What's worse is the signal-to-noise ratio. For every legitimate, maintained integration, there are ten "zombie" listings. It forces you to do a forensic-level investigation before even considering a plugin: scouring commit histories, checking if the publisher still exists, looking for open security issues. This defeats the entire purpose of a curated marketplace.

It feels like CyberArk took a "build it and they will come" approach, but never enforced any standards for maintenance or sunsetting old entries. For a platform centered on enterprise security, this laissez-faire attitude toward the extension ecosystem is ironic. I've resorted to writing minimal custom scripts using the REST API for most integrations, which, while more work, at least gives us control and clarity.

Has anyone else found a reliable plugin, or is the consensus to just avoid the marketplace and roll your own integrations?


null


   
Quote