Package Health

scheb/2fa-trusted-device

Usable with caveats: the package is licensed, clearly backed by a matching repository, and has a long release history, but recent repository activity is absent and no security policy or scanning is provided. Verify that v8.6.1 is the intended release because the stability signal reports v7.14.0 as latest.

Latest v8.6.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Maintainerscaution

Only one registry account has publishing access. That is a limited publishing base, although the matching source repository provides some continuity evidence.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last 3 months. This is a meaningful maintenance concern, though the recent push and release history provide some compensating evidence.

Repo toolingcaution

Composer is used for the build, but no security scanning tools are detected. The missing scanning reduces transparency around automated security checks.

Security policycaution

No SECURITY policy is present in the repository, leaving vulnerability reporting and response expectations undocumented.

Version stabilitycaution

The assessed release is marked stable and not prerelease, but the signal reports v7.14.0 as the latest version while the assessed version is v8.6.1, creating a material data-consistency concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Christian Scheb

Direct Dependencies

DependencyLast ReleaseScore
lcobucci/jwt
Version ^5.0
—
—
lcobucci/clock
Version ^3.0
—
—
scheb/2fa-bundle
Version self.version
—
—

Weekly Downloads

Info

Last Published
8 months ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform