The source has tests, a README, release notes, and a matching repository. One active contributor, one commit in three months, unpinned workflow actions, and no security policy limit resilience and transparency.
62%
Total Score
50
86
50
The package has only 2 releases, both on the same day, and none in the last 12 months; the latest registry release was over 2 years ago. This is a meaningful maintenance concern despite recent repository activity.
One contributor made 100% of the commits in the last 3 months, leaving maintenance dependent on a single active contributor. The repository is user-owned rather than organization-backed, so there is no provided organizational handoff signal to compensate.
Only 1 commit was recorded in the last 3 months, indicating a thin recent maintenance trail. The recent repository push is some compensating evidence, but it does not demonstrate sustained activity.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This matters for an authentication plugin and is not covered by another provided signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sylius/sylius Version ^1.12 | — | — |
scheb/2fa-bundle Version ^v5.13 | — | — |
scheb/2fa-qr-code Version ^5.13 | — | — |
scheb/2fa-google-authenticator Version ^5.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.