Package Health

ass/xmlsecurity

Its stable API, tests, license, and matching source repository support adoption. However, the last release was over 11 years ago, repository commits have stopped, and no security policy or scanning is present.

Latest v1.1.1PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has only three releases, with no release in the last 12 months and the latest published over 11 years ago. This is a substantial maintenance concern despite the repository remaining available.

Repo commit activitydanger

There were no commits and no active maintainers in the three months measured. Combined with the old registry release, this indicates the project is effectively inactive.

Repo toolingcaution

Composer is used for builds, but no security scanning tooling is present. The missing scanning is a modest transparency and maintenance gap rather than evidence of a failing build.

Security policycaution

The repository has no security policy, which is a meaningful gap for a library handling XML encryption and signatures because it gives consumers no documented vulnerability-reporting path.

Workflow auditcaution

No GitHub Actions workflows were found, so there are no workflow hazards to report. This also means the audit provides no evidence of automated repository checks.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Robert Richards
Andreas Schamberger

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
11 years ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform