The package has clear licensing, a focused dependency set, and a matching repository with tests and documented usage. Recent releases offset the quiet commit period, but workflow pinning and security-process gaps leave meaningful maintenance and supply-chain concerns.
67%
Total Score
63
100
94
83
Only one account has registry publish access, leaving a thin publishing base. This is a modest resilience concern for a user-owned project, although recent releases provide some compensation.
The repository is owned by an individual account rather than an organization, so the single registry maintainer represents a real continuity limitation rather than ordinary organization publishing hygiene.
The repository recorded no commits and no active maintainers in the last three months. The release on the latest push date partly offsets this, but the short-term activity gap remains a maintenance caution.
Composer build tooling is present, but no security-scanning tool was detected. For a package handling two-factor-authentication QR-code functionality, the missing automated security scanning is a meaningful hygiene gap.
The repository has no security policy. That weakens the documented path for reporting vulnerabilities, although it does not show that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pragmarx/google2fa Version ^8.0|^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.