The package includes tests, a README, a license, and only two runtime dependencies. Its workflow uses broad write permissions and seven unpinned actions, while the repository has no security policy; the organization backing provides some continuity.
64%
Total Score
67
100
81
50
The package is young at 102 days, with three releases and a median interval of about 17 days. That shows initial publishing activity, but the short history limits evidence of long-term maintenance.
One contributor made all commits in the last three months, giving the repository a complete concentration of recent activity. Organization backing partly reduces handoff risk, but the observed contributor base remains thin.
Only one commit was recorded in the last three months, with one active maintainer. The recent push is reassuring, but the low activity provides limited evidence of sustained maintenance.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy. For an authentication and identity library, that leaves vulnerability-reporting expectations unclear.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.