The package includes tests, a clear README, a matching license, and no install-time scripts. Its organization backing and focused dependency set provide useful context, but there is no security policy yet.
64%
Total Score
67
81
75
The package is newly published, with its first release and latest release on the same day and no established release cadence yet. This leaves maintenance maturity unproven.
One contributor made all two recent commits, creating a concentrated maintenance dependency. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository recorded two commits in the last three months, showing some recent activity but still too little history to establish sustained maintenance.
Composer build tooling is present, but no security-scanning tooling was detected. For a new authentication module, that is a modest transparency and maintenance gap.
The repository has no security policy. This is a meaningful documentation gap for a package handling passkey registration and authentication, although it does not by itself indicate unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=103.0 | — | — |
web-auth/webauthn-lib Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.