This release appears healthy and suitable to depend on: it is actively and frequently released, uses a stable major version, is not deprecated or archived, and is backed by a matching organization-owned repository with recent activity from three contributors. The package and repository include a README, changelog, tests, license, Composer build configuration, and workflow checks, while the dependency set is modest. The main reservations are the absence of a security policy and dedicated security-scanning tools, plus workflows that do not declare top-level token permissions; these are transparency and hardening gaps rather than evidence of abandonment. Low repository popularity and a single registry publisher are minor concerns, mitigated by the organization backing and observed multi-contributor activity.
88%
Total Score
100
100
89
80
The repository has only 4 stars, 3 forks, and 1 watcher, indicating limited external adoption and review; this is a supporting caution rather than a health verdict because observed maintenance is strong.
Composer build tooling is present, but no security-scanning tool was detected, leaving a security-process gap that lowers transparency somewhat.
No repository security policy was found, which leaves vulnerability-reporting and response expectations undocumented.
Both workflows lack top-level token-permission declarations. Although no write permissions are explicitly requested, least-privilege intent is not clearly documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^2.0 | — | — |
litesaml/lightsaml Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.