Package Health

openeuropa/oe_authentication

This is a mature, actively released, stable package with a clear license, substantial documentation, tests, changelog, appropriate repository linkage, and organization backing. The repository is not archived and the latest release and push are current, while dependencies remain limited and the workflow analysis found no dangerous patterns. The main concerns are that recent commit activity is concentrated entirely in one maintainer, the repository lacks a security policy and explicit workflow token permissions, and install/update lifecycle scripts increase operational complexity; these warrant review but do not outweigh the package's strong maintenance and transparency evidence.

Latest 1.22.0PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Lifecycle scriptscaution

post-install-cmd and post-update-cmd scripts add install-time execution risk and operational complexity, so consumers should inspect their behavior before adoption.

Repo bus factorcaution

One contributor made 100% of the five commits in the last 3 months. Organization backing provides some handoff capacity, but no second recently active contributor is shown, so concentration remains a maintenance risk.

Repo commit activitycaution

Five commits were made in the last 3 months, showing current activity, but all were produced by one active maintainer, limiting demonstrated maintenance breadth.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The build setup is established, while the missing scanning layer is a modest transparency and defense-in-depth gap.

Security policycaution

No security policy was found in the repository, leaving vulnerability reporting and response expectations less transparent for consumers.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
drupal/cas
Version ^3.0
—
—
drupal/core
Version ^10.3 || ^11.0
—
—

Weekly Downloads

Info

Last Published
15 days ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform