The repository has substantial recent work, three active contributors, tests, and an organization behind it. CI still uses six unpinned actions and installs packages outside a lockfile, while the project has no security policy.
68%
Total Score
100
83
50
Composer runs post-create, post-install, and post-update scripts. Install-time scripts can affect dependency installation and deserve review, although this signal alone does not show harmful behavior.
This package is brand new, with one release published today and no established release cadence. The active repository partly offsets the limited registry history, but version maturity remains unproven.
The project uses Composer and Make, but no security scanning tools were detected. That is a modest transparency and maintenance gap for a security-focused plugin.
No repository security policy was found. For a plugin covering authentication, passkeys, OAuth, and account protection, the absence of a documented vulnerability-reporting path is a real transparency gap.
CI analyzed completely and has no untrusted checkout or script-injection findings, but all six action references are unpinned and two high-confidence checks install packages outside a lockfile. These are workflow hygiene and reproducibility concerns, not severe risks on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0 | — | — |
sylius/sylius Version ^2.1 | — | — |
symfony/clock Version ^6.4|^7.4 | — | — |
scheb/2fa-totp Version ^7.13 | — | — |
endroid/qr-code Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.