The package has a clear MIT license, documented release notes, repository tests, and a small dependency surface. A missing security policy and absent automated security scanning reduce transparency for a security-sensitive OTP library.
68%
Total Score
50
100
88
83
Only one registry account has publish access. Because the project is backed by an individual user rather than an organization, there is limited publishing redundancy.
The repository recorded zero commits and zero active maintainers in the past three months, weakening evidence of ongoing maintenance after the latest release.
Composer build tooling is present, but no security scanning tools were detected. That is a transparency and assurance gap for an OTP package.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented for a package handling authentication-related codes.
The assessed release is marked as a stable, non-prerelease version, but the reported latest version is 5.3.4 while the assessed version is 7.0.0, creating a release-metadata inconsistency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.