Package Health

simplesamlphp/simplesamlphp-module-oauth

Unfit to use for a new dependency: the package is deprecated and its repository was archived in 2021. It is clearly documented as a legacy module, so even its tests and security tooling do not offset the lack of ongoing maintenance.

Latest v1.1.1PackagistPackagist

15%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

57

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk for a dependency.

Release historydanger

There have been no releases in about 5 years, and none in the last 12 months. That confirms the package is effectively inactive rather than merely released infrequently.

Repository archiveddanger

The linked repository is archived and was last pushed about 5 years ago, so it is no longer maintained. This outweighs the repository's otherwise clear package match and organization backing.

Security policycaution

No repository security policy is present, leaving disclosure and maintenance expectations undocumented. This is a secondary transparency gap given the stronger abandonment signals.

Token permissionscaution

The single workflow does not declare top-level token permissions, so its default permissions are not explicitly constrained. No write permissions or dangerous workflow patterns were observed, limiting this to a caution.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Olav Morken
Jaime Perez Crespo

Direct Dependencies

DependencyLast ReleaseScore
simplesamlphp/simplesamlphp
Version dev-master
simplesamlphp/composer-module-installer
Version >=1.1.6

Weekly Downloads

Info

Last Published
5 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform