Package Health

pressbooks/pressbooks-shibboleth-sso

Risky to adopt under this package name: Packagist marks the package abandoned and points to a replacement. The linked repository is active, tested, licensed, and recently released, but it does not match or mention this package, creating a significant identity and maintenance concern.

Latest 2.7.0PackagistPackagist

48%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned and names pressbooks/pressbooks-saml-sso as the replacement. This is a severe adoption concern even though the replacement appears to be actively maintained.

Repo package mentioncaution

The linked repository name does not match the package name and its README does not mention this package, so the relationship between the release and its source is not transparent. This materially increases supply-chain and maintenance uncertainty.

Security policycaution

The repository has no security policy. For an authentication integration, the absence of a documented vulnerability-reporting path is a genuine transparency gap.

Token permissionscaution

None of the five workflows declares top-level token permissions. Although no workflow was flagged for dangerous behavior, explicit permission scoping would provide stronger CI security hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Book Oven Inc.

Direct Dependencies

DependencyLast ReleaseScore
onelogin/php-saml
Version ^4.1
—
—
composer/installers
Version ^2.1
—
—
pressbooks/frontend-tools
Version ^1.0.0
—
—
phpcompatibility/php-compatibility
Version ^9.3
—
—

Weekly Downloads

Info

Last Published
6 months ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform