The project is backed by an organization, has a matching repository, tests, licensing, and security tooling. Adoption still carries avoidable risk from the lookalike identity, sparse releases, no commits in the past three months, and completely unpinned workflow actions.
48%
Total Score
83
100
85
67
The package is flagged as borrowing the identity of the much more established simplesamlphp/assert package, with 59 versus 227,951 monthly downloads; despite no artifact overlap, this is a serious consumer-confusion risk.
The package is about 10 years old but has only five releases, with a median interval of about two years. One release in the past year and the latest release provide some evidence of continued maintenance, but the cadence remains sparse.
There were no commits and no active maintainers during the past three months. The recent July push and March release partly offset this, but the short-term activity is still thin.
No repository security policy was found, leaving vulnerability-reporting expectations undocumented.
All three workflows were analyzed with no reported audit findings or unsafe-trigger sinks. However, all 24 action references are unpinned and one workflow grants top-level write access, creating avoidable reproducibility and token-scope concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-foundation Version ^7.4 | — | — |
simplesamlphp/simplesamlphp Version ~2.5@dev | — | — |
simplesamlphp/composer-module-installer Version ~1.7.0 | — | — |
simplesamlphp/simplesamlphp-module-consent Version ~1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.