Usable with caveats: the package is backed by an organization, has a matching repository with tests, security scanning, and a recent release. However, no commits were recorded in the last three months, and repository security documentation and workflow permission settings are incomplete.
72%
Total Score
67
100
94
75
The package has been maintained since 2019 with 10 releases, but only one release arrived in the last 12 months and releases are spaced about 145 days apart. This indicates a deliberate but relatively slow maintenance pace.
The repository recorded zero commits and zero active maintainers in the last three months. Although it was pushed about two months ago and released earlier this year, the recent lack of development lowers confidence in responsiveness.
There is only one open issue and no issue or pull-request activity in the last month. This is consistent with a small, quiet project but provides little evidence of active ongoing maintenance.
The repository has no security policy, so there is no documented route for reporting vulnerabilities. This is a transparency gap, though it is partly offset by the repository's automated security scanning.
Two workflows lack top-level token permissions and one declares top-level write access. The workflows show no dangerous execution patterns, but more restrictive explicit permissions would improve repository hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-client Version ^7.4 | — | — |
simplesamlphp/assert Version ^2.0 | — | — |
simplesamlphp/xml-cas Version ^2.5 | — | — |
symfony/http-foundation Version ^7.4 | — | — |
simplesamlphp/xml-common Version ^2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.