The repository is not archived and includes a clear license, release notes, and security scanning. Its single maintainer, absent recent commits, and unpinned workflow actions leave limited ongoing support.
60%
Total Score
50
86
50
The package has 14 releases since July 2016, but none in the last 12 months and the latest registry release was in June 2023. This indicates a substantial maintenance pause, partly offset by its established history.
There were no commits and no active maintainers in the last 3 months. Combined with the long gap since the latest registry release, this raises the risk that fixes and compatibility updates will not arrive promptly.
No repository security policy was found. For an authentication and access-control module, that reduces transparency around vulnerability reporting and response.
Version 0.3.2 is not marked as a prerelease, but the package remains below major version 1.0. That makes API stability less certain for a dependency with no recent releases.
The sole workflow was fully analyzed with no audit findings, no untrusted checkout or script-injection paths, and no top-level write permissions. However, all 3 action references are unpinned, leaving a modest workflow supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4 | — | — |
doctrine/orm Version ^2.10 | — | — |
paragonie/halite Version ^4.7| ^5.0 | — | — |
laminas/laminas-mvc Version ^3.3 | — | — |
laminas/laminas-http Version ^2.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.