The package has clear documentation, a long release history, and active organizational backing. Its automation has avoidable credential and pinning weaknesses, so keep workflow hygiene in mind when adopting it.
78%
Total Score
100
100
50
The repository has no security policy, leaving vulnerability-reporting expectations and response guidance undocumented. This is a transparency gap, but not evidence that maintenance has stopped.
All 25 analyzed action references are unpinned, and the audit found a high-confidence medium-severity secrets-inherit issue in php.yml; one workflow also grants top-level write access. There are no untrusted checkouts or script-injection findings, limiting the overall impact to workflow hygiene caution.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-46491 simplesamlphp/simplesamlphp-module-casserver is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 7.0.2. | 0.0.0 - 7.0.2 | High |
CVE-2025-65954 simplesamlphp/simplesamlphp-module-casserver is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 7.0.0-rc1 - 7.0.0-rc3 and 0.0.0 - 6.3.1. | 0.0.0 - 6.3.17.0.0-rc1 - 7.0.0-rc3 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
beste/clock Version ~3.0 | — | — |
symfony/http-kernel Version ~7.4 | — | — |
simplesamlphp/assert Version ~2.0 | — | — |
simplesamlphp/saml11 Version ~2.3 | — | — |
simplesamlphp/xml-cas Version ~2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.