The package is well documented and includes tests, release notes, and a clear MIT license. Its dependency footprint and install behavior look ordinary, with no deprecation or archived-repository warning.
70%
Total Score
67
94
75
The repository is owned by a user account rather than an organization, so the single-contributor concentration is not visibly backed by an organization that could hand off maintenance.
All 6 recent commits came from one contributor, giving the project a concentrated maintenance base and increasing continuity risk if that contributor becomes unavailable.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a transparency gap for an authentication library.
Version v0.2.2 is not a prerelease, but the package remains below 1.0, so its public API may still change more readily than a stable-major package.
The single workflow was fully analyzed, uses read-only permissions, and has no dangerous-trigger sinks or audit findings. However, all 6 action references are unpinned, leaving the workflow exposed to unexpected upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/utils Version ^3.2.10 || ^4.0.5 || ^4.1.0 | — | — |
tracy/tracy Version ^2.9.8 || ^2.10.9 || ^2.11.0 | — | — |
symfony/mailer Version ^4.4.49 || ^5 || ^6 || ^7 || ^8 | — | — |
robmorgan/phinx Version ^0.12.13 || ^0.13.4 || ^0.14.0 || ^0.15.5 || ^0.16.5 | — | — |
webmozart/assert Version ^1.10.0 || ^2.1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.