Risky to adopt: the package has had no registry release for over eight years and no recent repository activity. It remains backed by an organization with tests, documentation, and a matching repository, but the prerelease status and missing licensing and security-policy information add adoption risk.
44%
Total Score
50
100
67
50
The latest release was published over eight years ago, with no releases in the last 12 months. This strongly raises abandonment and compatibility risk despite the package having 11 releases overall.
The repository had zero commits and zero active maintainers during the last three months, reinforcing the long gap since the latest release and indicating a substantial abandonment risk.
No declared license or license file was found in the package or repository, leaving the legal terms for use unclear.
There are three open issues and one open pull request, but none were created or closed in the last month. This is consistent with an inactive maintenance process.
The repository has only four stars, seven forks, and two watchers. Low popularity is supporting caution rather than decisive evidence, but it provides little external maintenance signal.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
simplesamlphp/saml2 Version >=3.0 | — | — |
simplesamlphp/composer-module-installer Version ~1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.