The package has a clear license, tests, README, and a small dependency surface. Its source is not archived and matches the package, but there is no current maintenance evidence.
43%
Total Score
100
100
69
75
Only four releases exist, all from December 2015, with none in the last 12 months. This is strong evidence of abandonment for a library dependency.
The repository has one star, no forks, and one watcher. Low popularity is only supporting evidence, but it provides little external indication of ongoing adoption or review.
Composer is used for builds, but no security-scanning tooling is reported. This is a modest hygiene gap, not a primary reason to reject the release.
The repository is not archived, which is a positive, but it was last pushed in February 2017. That long period without repository activity materially raises maintenance risk.
The repository has no security policy. For an authentication component, that is a transparency and maintenance gap because vulnerability-reporting guidance is absent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gobline/session Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.