The package is documented, MIT-licensed, and backed by repository tests and release notes. Its missing security policy and unpinned workflow actions add maintenance and build-hygiene concerns.
58%
Total Score
50
71
50
The package has six releases since 2018, but none in the last 12 months; the latest release was about two and a half years ago. This indicates substantially slowed maintenance for a security-sensitive authentication library.
There were no commits and no active maintainers in the last three months, consistent with the long release gap. For an authentication library, this is a significant abandonment and maintenance concern.
The repository uses Composer build tooling, but no security scanning tools were detected. The absence of automated security scanning is a moderate hygiene gap for authentication software.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. That reduces transparency for a security-sensitive library.
The assessed version is 3.0.0-rc1, a prerelease, and recent prereleases make up one third of releases. Consumers do not have a final 3.0.0 release to prefer.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ~1.0 | — | — |
psr/http-server-handler Version ~1.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
phauthentic/password-hashers Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.