OAuth2, OpenID and OIDC for Solid Server implementations.
63%
Total Score
caution
Active releases and organization backing are offset by one active contributor and high-confidence workflow pinning and permission gaps.
Only one contributor made commits in the last 3 months, accounting for 100% of the 7 commits; organization backing provides some handoff capacity, but no second active contributor is shown.
The repository has no published security policy, leaving reporting and response expectations unclear for an authentication-focused library.
Version v0.15.0 is not a stable major release, so its pre-1.0 status implies less API stability, although it is not marked as a prerelease.
All 11 action references are unpinned, all four workflows grant top-level write permissions, and the audit found five high-confidence unpinned container-image findings. No untrusted checkout or script-injection sink was detected, but the workflow supply-chain and token hygiene remain significant concerns.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^4.1 | — | — |
web-token/jwt-core Version ^2.2 | — | — |
league/oauth2-server Version ^8.5.5 | — | — |
laminas/laminas-diactoros Version ^3.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.