The repository includes tests, release notes, a security policy, and a clear license. Single-person ownership, a very short history, and unpinned workflow actions leave limited evidence of durable maintenance and build hygiene.
68%
Total Score
50
81
83
Only one registry publisher is listed, and the repository is user-owned rather than organization-backed, leaving a thin apparent maintainer base for a security-sensitive authentication library.
The package was first released within the same day and has only two releases, so there is little evidence of an established maintenance pattern. The recent second release and accompanying notes provide some positive transparency.
No commits or active maintainers were observed in the last three months, but the repository itself was created and pushed within the same day as these releases. This is limited evidence rather than clear abandonment.
Composer build tooling is present, but no repository security-scanning tool was detected. That is a modest transparency and hygiene gap, not evidence that the package is unsafe.
Version v0.1.1 is not a stable major release, indicating an early-stage API and higher compatibility risk. It is not marked as a prerelease, which partly offsets that concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/simple-cache Version ^3.0 | — | — |
robrichards/xmlseclibs Version ^3.1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.