Clear licensing, tests, and release notes make the package easier to inspect, but missing security policy and install hooks add uncertainty. Use lightsaml/sp-bundle instead.
18%
Total Score
0
60
50
Packagist marks the entire package as abandoned and names lightsaml/sp-bundle as its replacement, making this release unsuitable for a new dependency.
The latest release was published in January 2016, with no releases in the last 12 months; this indicates long-term abandonment risk.
The repository had zero commits and zero active maintainers in the last 3 months, consistent with the package's abandoned status.
The package defines post-install and post-update Composer scripts, adding execution-time complexity for consumers even though this alone is not a severe risk.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/symfony Version >=2.3 <2.8 | — | — |
aerialship/lightsaml Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.