Package Health

italia/spid-php-lib

PHP package for SPID authentication

Latest v0.36PackagistPackagist

68%

Total Score

caution

Usable with caveats: recent security fixes are important, but maintenance is concentrated and workflow actions are unpinned.

Health Score Breakdown

Release historycaution

The package has 11 releases over nearly eight years but only one release in the last 12 months, indicating a slow current cadence; the recent release still shows ongoing maintenance.

Repo bus factorcaution

All 9 recent commits came from one contributor. Organization ownership provides some handoff capacity, but the observed maintenance base remains concentrated.

Security policycaution

The repository has no security policy, leaving reporting and response expectations undocumented for a security-sensitive authentication library.

Version stabilitycaution

v0.36 is not a stable major release, which signals API maturity risk even though it is not a prerelease and recent releases contain no prerelease versions.

Workflow auditcaution

The workflow was fully analyzed, uses read-only permissions, and has no untrusted checkout or script-injection findings. However, all 5 action references are unpinned, creating a reproducibility and supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Lorenzo Cattaneo
Paolo Greppi

Direct Dependencies

DependencyLast ReleaseScore
robrichards/xmlseclibs
Version ^3.1.5
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform