Usable with caveats: this is a licensed, stable module backed by the SimpleSAMLphp organization, with a matching repository and recent release. However, no commits or contributor activity were recorded in the last three months, and repository security-policy and workflow permission hygiene are incomplete.
72%
Total Score
75
94
67
The package has been maintained since 2019 with 11 releases and one release in the last 12 months. The relatively infrequent cadence is a modest maturity concern, but the latest release is recent enough to avoid an abandonment conclusion.
The repository recorded zero commits and zero active maintainers during the last three months. Although the recent release and June push provide some compensating evidence, the current maintenance pace warrants caution.
No repository security policy was found. This is a transparency gap for reporting vulnerabilities, though it is not by itself evidence that the package is unsafe.
Two workflows have no top-level token permissions declaration, and one declares write access. The workflows do not show dangerous patterns, but tighter least-privilege declarations would reduce maintenance and automation risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/oauth1-client Version ^1.11 | — | — |
simplesamlphp/assert Version ^2.0 | — | — |
symfony/http-foundation Version ^7.4 | — | — |
simplesamlphp/simplesamlphp Version ^2.5@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.