Usable with caveats: it is a stable, recently released package with a matching, active repository and a modest dependency set. Maintenance is concentrated in one contributor, recent development is minimal, and the repository has no security policy or scanning tools.
68%
Total Score
50
100
94
83
All recent commits come from one contributor, and the repository is owned by an individual rather than an organization, making maintenance vulnerable to that person's availability.
Only one commit was recorded in the last three months and only one maintainer was active, showing limited recent development despite the recent repository push.
Composer build tooling is present, but no security scanning tools are reported, leaving a transparency and maintenance-control gap for a security-related MFA extension.
The repository has no security policy, which is a meaningful gap for a package handling multi-factor authentication and security-sensitive account flows.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^11 || ^12 || ^13 || 14.*.*@dev | — | — |
bacon/bacon-qr-code Version ^2.0.4 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.