LightSAML 6.0.0 appears to be a healthy dependency: it has a long release history dating back about 11 years, seven releases in the last 12 months, a stable non-prerelease major version, and no registry deprecation. The linked organization-owned repository is active and directly matches the package, with 25 commits from three contributors in the last three months, current publication activity, tests, changelog, CI workflows, and a substantial source tree. The main reservations are concentrated commit activity, no repository security policy or automated security scanning, and workflows without explicit top-level token permissions; these are meaningful hygiene gaps but do not outweigh the strong maintenance and transparency evidence.
88%
Total Score
90
100
94
80
Three contributors are active, but the top contributor authored 88% of recent commits, creating concentration risk. The organization-owned project and continued activity from two other contributors partly mitigate, but do not eliminate, this concern.
Composer build tooling is present, but no security scanning tools were detected. This is a security-process hygiene gap rather than evidence of poor maintenance by itself.
The repository has no security policy, reducing transparency about vulnerability reporting and response procedures.
Both workflows lack top-level token permission declarations, although neither requests top-level write permissions. Explicit least-privilege declarations would improve CI security hygiene.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-171680 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. litesaml/lightsaml is vulnerable to Use of a Broken or Risky Cryptographic Algorithm in versions 0.1.0 - 4.6.1. | 0.1.0 - 4.6.1 | Low |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
litesaml/schemas Version ^3.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^2.0 | — | — |
phpseclib/phpseclib Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.