The package has clear licensing, tests, documentation, and active organizational ownership. Its recent lack of commits and completely unpinned workflow actions weaken maintenance and build-reproducibility confidence.
65%
Total Score
75
100
100
67
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Because the package is still relatively young and had a recent release, this is a meaningful maintenance caution rather than evidence of abandonment on its own.
The repository has no security policy. This is a transparency and reporting gap, though it is less serious than an archived project or absent security tooling.
The single workflow was fully analyzed with no injection or high-severity findings, but all 15 action references are unpinned and the workflow grants top-level write permissions. The broad token scope is not paired with an observed untrusted trigger, so this remains a hygiene caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
simplesamlphp/simplesamlphp Version ^v2.3 | — | — |
paragonie/constant_time_encoding Version ^3.0 | — | — |
simplesamlphp/composer-module-installer Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.