Package Health

simplesamlphp/simplesamlphp-module-authtwitter

Usable with caveats: this is a licensed, stable module backed by the SimpleSAMLphp organization, with a matching repository and recent release. However, no commits or contributor activity were recorded in the last three months, and repository security-policy and workflow permission hygiene are incomplete.

Latest v1.3.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package has been maintained since 2019 with 11 releases and one release in the last 12 months. The relatively infrequent cadence is a modest maturity concern, but the latest release is recent enough to avoid an abandonment conclusion.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers during the last three months. Although the recent release and June push provide some compensating evidence, the current maintenance pace warrants caution.

Security policycaution

No repository security policy was found. This is a transparency gap for reporting vulnerabilities, though it is not by itself evidence that the package is unsafe.

Token permissionscaution

Two workflows have no top-level token permissions declaration, and one declares write access. The workflows do not show dangerous patterns, but tighter least-privilege declarations would reduce maintenance and automation risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tim van Dijen

Direct Dependencies

DependencyLast ReleaseScore
league/oauth1-client
Version ^1.11
—
—
simplesamlphp/assert
Version ^2.0
—
—
symfony/http-foundation
Version ^7.4
—
—
simplesamlphp/simplesamlphp
Version ^2.5@dev
—
—

Weekly Downloads

Info

Last Published
7 months ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform