The repository remains unarchived and includes tests plus release notes for this version. Licensing and dependency scope are clear, but workflow references are unpinned and no security policy is published.
62%
Total Score
50
100
86
50
The package has 24 releases over nearly six years, but none in the last 12 months and its latest registry release was over a year ago. The recent repository push provides some compensating evidence, but does not show a current registry release cadence.
There were no commits and no active maintainers in the last three months. The recent push shown by repository status partly offsets this, but current development activity is still thin.
The repository has no published security policy. For an authentication package, this is a meaningful transparency gap because it gives maintainers' vulnerability-reporting process no visible documentation.
This release is a release candidate, while the registry reports v1.0.4 as the latest stable version. That makes this version less suitable when a stable dependency is required.
The only workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but both of its two action references are unpinned. That leaves avoidable workflow supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version ^6 | — | — |
silverstripe/totp-authenticator Version ^6 | — | — |
nswdpc/silverstripe-pwnage-hinter Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.