This release has strong evidence of an established and actively published project: it is over 8 years old, has 39 releases, shipped 3 releases in the last 12 months, is stable, backed by the OpenEuropa organization, linked to a non-archived repository, and includes substantial documentation, tests, changelog, licensing, and build structure. However, the package is explicitly marked abandoned on Packagist with a replacement package, and the linked repository does not match the package name or mention it in its README, creating material uncertainty about whether this release is the intended dependency. Recent work is also concentrated in one contributor, while repository security-policy and workflow permission hygiene are incomplete. Developers should prefer the stated replacement package unless compatibility requirements make this package unavoidable.
45%
Total Score
63
100
75
70
Packagist marks the package as abandoned and identifies openeuropa/oe_authentication as its replacement. Although the replacement provides a clear migration path, depending on this package carries a substantial lifecycle risk.
The package defines post-install-cmd and post-update-cmd Composer scripts. These require review in a dependency-sensitive environment, but the signal alone does not establish an unsafe or unusually invasive workflow.
All 5 recent commits came from one contributor, giving a 100% top-contributor share. Organizational ownership partly mitigates this concentration, but it remains a genuine continuity risk.
The repository recorded 5 commits in the last 3 months, showing current activity, but only one active maintainer produced them. The activity is positive but limited in breadth.
Two issues were closed and one pull request was merged in the last month, indicating some ongoing maintenance, although there were no new issues or pull requests and 10 issues plus 8 pull requests remain open.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/cas Version ^3.0 | — | — |
drupal/core Version ^10.3 || ^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.