The stable major release and recent repository push provide some continuity, while Dependabot and a matching, organization-backed repository add transparency. Unpinned workflow actions and no security policy leave meaningful maintenance and build-hygiene concerns.
62%
Total Score
75
100
94
75
The package has three releases over about 3 years and 8 months, with no releases in the last 12 months and a median interval of about 446 days. This indicates slow maintenance, although the latest release is not yet long-abandoned.
The repository recorded zero commits and zero active maintainers in the last 3 months. This is a concrete recent-maintenance gap, partly offset by the repository's recorded March 2026 push.
There are no open issues but three open pull requests, with no new or merged pull requests in the last month. This offers limited evidence of active review and leaves some maintenance work unresolved.
The repository has no security policy. For an authorization helper, this reduces transparency around vulnerability reporting and maintenance handling.
The sole workflow was fully analyzed with no audit findings, no untrusted checkouts, and no injection sinks. However, all 3 of 3 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.0 || ^3.0 | — | — |
webmozart/assert Version ^1.11.0 | — | — |
laminas/laminas-session Version ^2.24 | — | — |
jield-webdev/bjy-authorize Version ^3.0 | — | — |
laminas/laminas-cache-storage-adapter-filesystem Version ^2.5 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.