Usable with caveats: it is a stable, licensed module from a matching organization-owned repository with tests and security tooling. Recent repository activity has paused, and workflow permissions plus the lack of a security policy reduce confidence in ongoing maintenance practices.
72%
Total Score
75
50
100
80
Six runtime dependencies are reasonable for a SimpleSAMLphp module, but the package depends on several framework and module components, increasing the need to keep the dependency chain maintained.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful sign that maintenance may be intermittent even though a recent release and push exist.
There is one open issue and one open pull request, but neither issue nor pull-request activity changed in the last month, providing limited evidence of active community maintenance.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented.
Two workflows lack top-level token permissions and one declares top-level write access, which is weaker least-privilege hygiene than expected for repository automation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
simplesamlphp/assert Version ~2.0 | — | — |
symfony/http-foundation Version ^7.4 | — | — |
simplesamlphp/simplesamlphp Version ~2.5@dev | — | — |
simplesamlphp/composer-module-installer Version ~1.7 | — | — |
simplesamlphp/simplesamlphp-module-consent Version ~1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.