The package has clear documentation, tests, a changelog, and an active organization-backed project. Its early v0 development and unpinned workflow actions leave more maturity and build-integrity risk than an established dependency.
72%
Total Score
100
100
79
100
The package is only 46 days old with three releases and a median interval of about 4 days, showing active early development but limited history for judging durability.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest gap in automated security hygiene.
Version v0.2.1 is not a prerelease, but the major version is still 0, so compatibility and API stability remain less established than for a mature 1.x release.
Both workflows were analyzed successfully and use read-only permissions, with no untrusted checkout, injection, or audit findings. However, all four action references are unpinned, weakening reproducibility and build-integrity controls.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
web-auth/webauthn-lib Version ^5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.