Its documentation, repository tests, and organizational ownership provide useful support. The recent release and non-archived repository help, but workflow hardening and explicit security-policy coverage need improvement.
63%
Total Score
75
94
50
The project is mature, with 24 releases over roughly seven years, but only one release in the last 12 months. The latest release is recent, which partly offsets the slower recent cadence.
The repository had zero commits and zero active maintainers in the last three months. The recent registry release and June 2026 repository push provide some compensation, but current maintenance activity is still thin.
No repository security policy was found. For an authentication module, the lack of a documented vulnerability-reporting process is a meaningful transparency gap.
All 24 analyzed action references are unpinned, and the audit found high-confidence secrets-inherit findings in php.yml. One workflow also grants top-level write access; these are workflow hygiene and credential-scope concerns, but no untrusted checkout or script-injection sink was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/ldap Version ~7.4 | — | — |
simplesamlphp/assert Version ~2.0 | — | — |
symfony/security-core Version ~7.4 | — | — |
symfony/http-foundation Version ~7.4 | — | — |
simplesamlphp/simplesamlphp Version ~2.5@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.