Usable with caveats: this is a newly published package with no track record beyond its first release, so maintenance is not yet proven. It has clear licensing, a matching organization-owned repository, and a useful README, but no tests or security policy are visible.
62%
Total Score
83
50
75
90
The package has two clearly named runtime dependencies, drupal/saml_sp and cubear/cwd_saml_mapping, with no development dependencies. The dependency surface is understandable, though the module relies on a required patch to saml_sp as documented in its README.
This is the first and only release, published 0 days ago, so there is no release history or demonstrated maintenance cadence yet. That is a meaningful maturity concern, though not evidence of abandonment for a package created today.
There were no commits in the last three months and no active maintainers in that period. Because the repository was created and pushed today, this primarily reflects the package's lack of history rather than confirmed abandonment.
The repository has zero stars, forks, and watchers. This offers no external adoption evidence, but popularity is supporting evidence rather than a requirement for a small specialized package.
Composer is used as a build tool, which fits the package ecosystem, but no security scanning tools are configured. The missing scanning is a modest transparency gap for a newly published package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
drupal/saml_sp Version ^4.3 | — | — |
cubear/cwd_saml_mapping Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.