The bundle includes tests, release notes, and an MIT license, with organization backing. Its workflows use three unpinned actions, installation runs a post-install script, and the repository has no security policy; the package-repository link also merits verification.
58%
Total Score
75
88
50
A post-install command runs during installation, adding execution during dependency setup and therefore a modest supply-chain and reproducibility concern.
This is the package's only release, published about six months ago, so there is not yet enough release history to show sustained maintenance.
There were no commits and no active maintainers in the past three months. Although this is a new package, the absence of follow-up activity weakens evidence of ongoing maintenance.
The repository name does not match the package name and its README does not mention the package, so the source relationship is not clearly established by the collected evidence.
No security policy was found in the repository, reducing transparency for reporting and handling vulnerabilities in an authentication-related bundle.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.3 || ^7.0 | — | — |
symfony/config Version ^6.3 || ^7.3 | — | — |
symfony/mailer Version ^6.3 || ^7.3 | — | — |
symfony/http-client Version ^6.3 || ^7.3 | — | — |
symfony/http-kernel Version ^6.3 || ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.