Unfit to use for a new dependency: the package is deprecated and its repository was archived in 2021. It is clearly documented as a legacy module, so even its tests and security tooling do not offset the lack of ongoing maintenance.
15%
Total Score
100
57
75
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk for a dependency.
There have been no releases in about 5 years, and none in the last 12 months. That confirms the package is effectively inactive rather than merely released infrequently.
The linked repository is archived and was last pushed about 5 years ago, so it is no longer maintained. This outweighs the repository's otherwise clear package match and organization backing.
No repository security policy is present, leaving disclosure and maintenance expectations undocumented. This is a secondary transparency gap given the stronger abandonment signals.
The single workflow does not declare top-level token permissions, so its default permissions are not explicitly constrained. No write permissions or dangerous workflow patterns were observed, limiting this to a caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
simplesamlphp/simplesamlphp Version dev-master | — | — |
simplesamlphp/composer-module-installer Version >=1.1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.