The package is licensed, tested, and backed by an organization. Its workflow is tightly audited, with read-only permissions and pinned actions. The short history and concentrated authorship leave maintenance capacity unproven.
68%
Total Score
67
93
83
This is the first release, published 0 days ago, so there is no track record for sustained maintenance or release stability.
All 7 recent commits came from one contributor, concentrating maintenance responsibility; organization backing provides some ability to hand work off but does not demonstrate a second active maintainer.
Seven commits in the last 3 months show recent activity, but the evidence covers only a newly created project and does not establish long-term continuity.
No repository security policy was found, a minor transparency gap for an HTTP authentication component, though the available audit tooling and tests partly offset it.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
componenta/auth Version ^3.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^2.0 | — | — |
componenta/identity Version ^1.0.1 | — | — |
psr/http-server-handler Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.