Package Health

simplesamlphp/simplesamlphp-module-authx509

Its documentation, repository tests, and organizational ownership provide useful support. The recent release and non-archived repository help, but workflow hardening and explicit security-policy coverage need improvement.

Latest v2.1.0PackagistPackagist

63%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The project is mature, with 24 releases over roughly seven years, but only one release in the last 12 months. The latest release is recent, which partly offsets the slower recent cadence.

Repo commit activitycaution

The repository had zero commits and zero active maintainers in the last three months. The recent registry release and June 2026 repository push provide some compensation, but current maintenance activity is still thin.

Security policycaution

No repository security policy was found. For an authentication module, the lack of a documented vulnerability-reporting process is a meaningful transparency gap.

Workflow auditcaution

All 24 analyzed action references are unpinned, and the audit found high-confidence secrets-inherit findings in php.yml. One workflow also grants top-level write access; these are workflow hygiene and credential-scope concerns, but no untrusted checkout or script-injection sink was found.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Joost van Dijk
Thijs Kinkhorst
Tim van Dijen

Direct Dependencies

DependencyLast ReleaseScore
symfony/ldap
Version ~7.4
—
—
simplesamlphp/assert
Version ~2.0
—
—
symfony/security-core
Version ~7.4
—
—
symfony/http-foundation
Version ~7.4
—
—
simplesamlphp/simplesamlphp
Version ~2.5@dev
—
—

Weekly Downloads

Info

Last Published
6 months ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform