Regular releases, a stable version, clear licensing, tests, and security tooling support continued maintenance. The source repository is active and clearly matches this package.
68%
Total Score
50
50
100
100
The release has 14 runtime dependencies, including core Symfony components and authentication libraries; this is a substantial integration surface but is coherent for a Symfony two-factor authentication bundle.
The package and repository are owned by the same individual account rather than an organization, so there is no organizational handoff capacity to offset the concentrated contributor base.
All recent commit activity comes from one contributor, creating a meaningful continuity risk if that maintainer becomes unavailable.
Only one commit was recorded in the last 3 months, showing recent activity but a slower maintenance pace than the strong release history suggests.
All 10 analyzed action references are unpinned, and a high-confidence finding reports a floating latest container image in split.yaml. The audit was complete and found no untrusted checkout or script-injection path, but the image pinning gap remains a supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^5.0 | — | — |
lcobucci/clock Version ^3.0 | — | — |
symfony/config Version ^7.4 || ^8.0 | — | — |
spomky-labs/otphp Version ^11.4 | — | — |
symfony/http-kernel Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.