Risky to adopt under this package name: Packagist marks the package abandoned and points to a replacement. The linked repository is active, tested, licensed, and recently released, but it does not match or mention this package, creating a significant identity and maintenance concern.
48%
Total Score
100
81
67
Packagist marks the entire package as abandoned and names pressbooks/pressbooks-saml-sso as the replacement. This is a severe adoption concern even though the replacement appears to be actively maintained.
The linked repository name does not match the package name and its README does not mention this package, so the relationship between the release and its source is not transparent. This materially increases supply-chain and maintenance uncertainty.
The repository has no security policy. For an authentication integration, the absence of a documented vulnerability-reporting path is a genuine transparency gap.
None of the five workflows declares top-level token permissions. Although no workflow was flagged for dangerous behavior, explicit permission scoping would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
onelogin/php-saml Version ^4.1 | — | — |
composer/installers Version ^2.1 | — | — |
pressbooks/frontend-tools Version ^1.0.0 | — | — |
phpcompatibility/php-compatibility Version ^9.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.