It includes tests, documentation, and a matching MIT license. The small dependency set is straightforward, but there is no security policy and repository ownership remains individual.
20%
Total Score
25
100
75
50
The latest release was published in November 2014, and there have been no releases in over 11 years. This is strong evidence of abandonment for a security-sensitive authentication bundle.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and offering no evidence of ongoing maintenance.
The package runs post-install and post-update scripts. These add installation complexity and supply-chain exposure, though the signal does not show that the scripts are malicious or unusually dangerous.
There were no new issues, closed issues, pull requests, or merged pull requests in the last month. This does not prove abandonment alone, but it provides no compensating maintenance activity.
The repository name does not exactly match the package name and its README does not mention the package, creating some uncertainty about repository alignment. The source tree and README still describe the same SAML bundle, which partly reduces this concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/symfony Version ~2.2 | — | — |
pmaglione/lightsaml Version 1.0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.