The package includes a README, tests, MIT licensing, and only one runtime dependency. Its organization-owned repository is not archived and matches the package, but it lacks a security policy and has little visible adoption.
62%
Total Score
100
100
75
88
The latest registry release was in August 2016, with no releases in the last 12 months, creating a substantial maintenance and freshness concern. The repository was pushed recently, which partly offsets the lack of registry releases but does not show a current package release cadence.
The repository has only 3 stars and 2 forks, indicating limited visible adoption. Popularity is supporting evidence rather than a health verdict, so this is a modest concern rather than a severe risk.
Composer is used as a build tool, which fits the package ecosystem, but no security scanning tooling is present. This is a hygiene gap with limited weight because other repository evidence is available.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled for an authentication library.
The assessed version is not a prerelease, but it remains on the 0.x line, so compatibility stability is less established than for a stable major release.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.