There is no published security policy, though the repository includes tests and automated dependency scanning. Organization ownership provides some continuity, and the package is clearly documented for its intended SAML 1.1 use.
70%
Total Score
83
100
75
All 20 recent commits came from one contributor. Organization ownership offers some handoff capacity, but no second active contributor is evidenced, so maintenance continuity remains a concern.
No security policy file was found in the repository. For a library handling SAML data, this reduces transparency around vulnerability reporting and response.
All 23 analyzed action references are unpinned, and the audit found two high-confidence secrets-inherit findings; one workflow also grants top-level write access. No untrusted checkout or script-injection sink was found, limiting the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~3.0 | — | — |
psr/clock Version ~1.0 | — | — |
simplesamlphp/assert Version ~3.0 | — | — |
simplesamlphp/xml-common Version ~3.0 | — | — |
simplesamlphp/xml-security Version ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.