Package Health

cemerson/auth

The source remains identifiable and licensed, with a structured tree and no install-time scripts. More than five years have passed since the last release, repository activity is sparse, and no security policy or scanning is provided.

Latest v0.8PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The latest release was published in June 2021, and there have been no releases in over five years. That is a substantial abandonment concern for an authentication library, despite the repository remaining available.

Repo issue activitycaution

There have been no new or closed issues in the last month and no merged pull requests, with one pull request still open. This provides little evidence of active maintenance.

Repo popularitycaution

The repository has only 1 star, 1 fork, and 1 watcher. Popularity is not required for a healthy small package, but these figures provide little supporting evidence of community review or adoption.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured. For authentication software, the missing security review automation is a meaningful hygiene gap.

Security policycaution

The repository has no security policy. That reduces transparency about how vulnerabilities are reported and handled, which matters more for an authentication library.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Chris Emerson

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.1
—
—
cemerson/clock
Version ^1.2
—
—
paragonie/password_lock
Version ^3.0
—
—

Weekly Downloads

Info

Last Published
5 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform