Package Health

simplesamlphp/simplesamlphp-module-webauthn

A PHP implementation of a FIDO2 / WebAuthn authentication agent

Latest v2.5.1PackagistPackagist

44%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Name lookalikedanger

The package is flagged as borrowing the identity of the much more established simplesamlphp/saml2 package, with 256,649 monthly downloads versus 31 and borrows_lookalike_identity set to true. Although artifact overlap is zero and the README does not identify it as the lookalike, this remains a severe adoption risk.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers over the last three months. That is a meaningful maintenance warning despite the package having released four times in the last 12 months.

Security policycaution

The linked repository has no security policy. This reduces vulnerability-reporting transparency for an authentication module, although Dependabot and composer-audit provide some compensating security tooling.

Workflow auditcaution

All 24 analyzed action references are unpinned, and one workflow grants top-level write permissions; no untrusted trigger or audit finding was reported. The repository is not exposed to the most serious workflow risks, but its build inputs are harder to control.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Stefan Winter

Direct Dependencies

DependencyLast ReleaseScore
web-auth/cose-lib
Version ~4.4
—
—
simplesamlphp/assert
Version ~2.0
—
—
spomky-labs/cbor-php
Version ~3.2
—
—
symfony/http-foundation
Version ~7.4
—
—
spomky-labs/pki-framework
Version ~1.4
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform