Risky to depend on: the package has had no release since 2015 and no repository commits in the last three months. It is not deprecated or archived and has usable documentation, but the long-standing inactivity makes maintenance and compatibility a serious liability.
32%
Total Score
38
83
83
The package has only three releases, with the latest published in September 2015 and none in the last 12 months. This long release gap is a strong abandonment and compatibility concern.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the latest push having occurred in April 2016. This indicates prolonged inactivity for an authentication module.
Only one registry publishing account is listed, limiting apparent publishing capacity. The repository is user-owned rather than organization-owned, so there is no provided backing signal to offset the narrow maintainer base.
The linked repository is owned by an individual account, with no organization backing shown. Combined with the long inactivity, this provides little evidence of ongoing project support.
There were no new or closed issues or pull requests in the last month, while two issues and three pull requests remain open. The unresolved backlog adds to the maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
openid/php-openid Version dev-master#ee669c6a9d4d95b58ecd9b6945627276807694fb as 2.2.2 | — | — |
composer/installers Version * | — | — |
simplesamlphp/saml2 Version ~0.3 | — | — |
silverstripe/framework Version 3.1.* | — | — |
simplesamlphp/xmlseclibs Version 1.3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.