Fork of web-auth/webauthn-lib that supports Android FIDO2/Passkey attestations
58%
Total Score
33
50
72
88
The repository had zero commits and zero active maintainers in the last three months, consistent with the long gap since the latest release and indicating stalled maintenance.
The package has 17 runtime dependencies, including cryptographic, parsing, and process-related components. This is a meaningful dependency surface for a security-sensitive authentication library, though the signal does not show that any dependency is unsafe.
The published artifact omits tests and a changelog, which is normal packaging practice, but the repository also reports no tests. The missing repository test evidence is a modest concern for an authentication library, while no release notes are available to offset it.
The package and repository are owned by the same individual account. There is no organization backing shown, so the project appears dependent on a small ownership base.
The package has 76 releases over about seven years, but none in the last 12 months and the latest release was published roughly two and a half years ago. This strong historical cadence is offset by the current inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
ramsey/uuid Version ^3.8|^4.0 | — | — |
beberlei/assert Version ^3.2 | — | — |
fgrosse/phpasn1 Version ^2.1 | — | — |
psr/http-client Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.