The package is small and focused, with a straightforward Composer setup and clear installation notes. Maintenance is recent but very thin, with one commit from one contributor in the last three months and no security policy. Organization backing and release notes provide some reassurance.
68%
Total Score
67
100
89
83
One contributor made all commits in the last three months, concentrating current maintenance in a single person. The organization-owned repository provides some handoff capacity, so this is a caution rather than a severe risk.
The repository recorded only one commit in the last three months. This is evidence of limited recent maintenance capacity, even though it is not complete inactivity.
The repository has four stars, one fork, and one watcher, showing a small user and contributor footprint. Popularity is supporting evidence only, but it reinforces the thin-maintenance picture.
Composer is used for the build, but no security scanning tooling is present. The missing scanning is a hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This reduces transparency for a package that handles identity-verification flows.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.