Healthy and actively maintained, but use this release candidate only if you need its PHP 8.5 and DOM API changes. The project has strong release and commit activity, while contributor activity is concentrated and the repository lacks a security policy.
82%
Total Score
88
100
94
67
Three contributors were active in the last three months, but one made 87.5% of commits. The organization backing provides some handoff capacity, yet the current work remains heavily concentrated.
No repository security policy was found. For a library handling SAML authentication and assertions, the absence of published vulnerability-reporting guidance is a transparency gap.
Three of four workflows lack top-level token permissions, and one workflow declares write access. Although no dangerous workflow patterns were detected, the permissions are less explicit and restrictive than ideal.
The assessed version is v7.0.0-rc1, while the latest stable version reported is v6.2.4. As a release candidate, it carries more compatibility risk than the established stable line, despite only 5% of recent releases being prereleases.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-375167 simplesamlphp/saml2 is vulnerable to Authentication Bypass in versions 6.2.2 - 6.2.3. | 6.2.2 - 6.2.3 | High |
CVE-2026-49289 simplesamlphp/saml2 is vulnerable to Uncontrolled Resource Consumption in versions 4.20.0 - 4.20.2 and 0.0.0 - 4.19.2. | 0.0.0 - 4.19.24.20.0 - 4.20.2 | High |
CVE-2026-49283 simplesamlphp/saml2 is vulnerable to Improper Certificate Validation in versions 6.0.0 - 6.2.1, 5.0.0 - 5.0.6, 4.20.0 - 4.20.2 and 0.0.0 - 4.19.3. | 0.0.0 - 4.19.34.20.0 - 4.20.25.0.0 - 5.0.6 +1 more | High |
CVE-2025-27773 simplesamlphp/saml2 is vulnerable to Improper Verification of Cryptographic Signature in versions 5.0.0-alpha.1 - 5.0.0-alpha.19 and 0.0.0 - 4.16.15. | 0.0.0 - 4.16.155.0.0-alpha.1 - 5.0.0-alpha.19 | High |
CVE-2024-52806 simplesamlphp/saml2 is vulnerable to Improper Restriction of XML External Entity Reference in versions 0.0.0 - 4.6.14. | 0.0.0 - 4.6.14 | High |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~3.0 | — | — |
psr/clock Version ~1.0 | — | — |
nyholm/psr7 Version ~1.8 | — | — |
psr/http-message Version ~2.0 | — | — |
simplesamlphp/assert Version ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.