The license declaration conflicts with the repository license, and the project has no security policy or security scanning. It is not deprecated, has a matching repository, and includes useful documentation.
53%
Total Score
50
75
83
The package has 20 releases since 2018, but none in the last five years; that substantially raises maintenance and abandonment concerns.
The manifest declares MPL-2.0 while the repository license file is recognized as Apache-2.0. This mismatch creates a real licensing and transparency concern.
There were no commits and no active maintainers in the last three months, which is a meaningful sign of slowed maintenance for an authentication module.
Composer is used for builds, but the repository reports no security scanning tools, leaving a notable security-maintenance gap.
The repository has no security policy, reducing transparency about how vulnerability reports are handled for security-sensitive authentication code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpmailer/phpmailer Version ^6 | — | — |
laminas/laminas-form Version ^2.15 | — | — |
laminas/laminas-text Version ^2.7 | — | — |
laminas/laminas-captcha Version ^2.9 | — | — |
laminas/laminas-session Version ^2.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.