The package includes a substantial README, a broad automated test suite, and clear licensing. Its organization-backed repository is small and lightly exercised, leaving longer-term maintenance and release maturity uncertain.
61%
Total Score
67
79
75
This is a 41-day-old package with only one release, so there is not yet enough release history to demonstrate sustained maintenance or compatibility stability.
All recent commits came from one contributor, creating a concentrated maintenance dependency. Organization backing provides some handoff capacity, but no second active contributor is evidenced.
Only one commit from one active maintainer was recorded over the past three months. For a package this new, that may reflect its short history, but it still provides little evidence of sustained maintenance capacity.
Composer build tooling is present, but no security-scanning tool was detected. That leaves an avoidable gap in ongoing dependency and code-quality oversight.
The repository has no security policy, so users are not given a documented channel or process for reporting vulnerabilities. This is a transparency and maintenance gap for authentication and Teams integration code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^7.0 || ^8.0 | — | — |
symfony/http-kernel Version ^7.0 || ^8.0 | — | — |
symfony/security-core Version ^7.0 || ^8.0 | — | — |
web-token/jwt-library Version ^4.0 | — | — |
symfony/cache-contracts Version ^2.5 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.