Usable with caveats: this is a well-documented, tested, MIT-licensed early alpha with a matching source repository. However, it has published only once, had no commits in the last three months, and lacks security policy and automated security scanning for an identity package.
57%
Total Score
25
50
78
83
The repository recorded zero commits and zero active maintainers during the last 3 months. For an early alpha security-sensitive package, this is a meaningful maintenance and abandonment concern.
Seven runtime dependencies, including WebAuthn, COSE, OTP, QR-code, and a related Nexus package, create meaningful dependency surface for an authentication library, though the profile is not excessive on its own.
The registry namespace and repository owner match, which supports clear ownership, though the owner is an individual account rather than an organization and therefore provides limited institutional backing.
Only one release exists, and there has been no new release for about 4.5 months despite the package being about 4.5 months old. This leaves maintenance continuity and maturity unproven.
The repository has zero stars, forks, and watchers, providing no community validation or visible adoption support. Popularity is only supporting evidence, so this is a modest concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
endroid/qr-code Version ^5.0 | — | — |
spomky-labs/otphp Version ^11.3 | — | — |
web-auth/cose-lib Version ^4.2 | — | — |
web-auth/webauthn-lib Version ^4.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.