Package Health

iberfacil/eidas-cert-auth

The repository includes tests, release notes, a security policy, and a clear license. Single-person ownership, a very short history, and unpinned workflow actions leave limited evidence of durable maintenance and build hygiene.

Latest v0.1.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Maintainerscaution

Only one registry publisher is listed, and the repository is user-owned rather than organization-backed, leaving a thin apparent maintainer base for a security-sensitive authentication library.

Release historycaution

The package was first released within the same day and has only two releases, so there is little evidence of an established maintenance pattern. The recent second release and accompanying notes provide some positive transparency.

Repo commit activitycaution

No commits or active maintainers were observed in the last three months, but the repository itself was created and pushed within the same day as these releases. This is limited evidence rather than clear abandonment.

Repo toolingcaution

Composer build tooling is present, but no repository security-scanning tool was detected. That is a modest transparency and hygiene gap, not evidence that the package is unsafe.

Version stabilitycaution

Version v0.1.1 is not a stable major release, indicating an early-stage API and higher compatibility risk. It is not marked as a prerelease, which partly offsets that concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Marco Gavilán

Direct Dependencies

DependencyLast ReleaseScore
psr/simple-cache
Version ^3.0
—
—
robrichards/xmlseclibs
Version ^3.1.5
—
—

Weekly Downloads

Info

Last Published
3 hours ago
Created
3 hours ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform