A PHP implementation of a FIDO2 / WebAuthn authentication agent
44%
Total Score
83
89
83
The package is flagged as borrowing the identity of the much more established simplesamlphp/saml2 package, with 256,649 monthly downloads versus 31 and borrows_lookalike_identity set to true. Although artifact overlap is zero and the README does not identify it as the lookalike, this remains a severe adoption risk.
The repository recorded zero commits and zero active maintainers over the last three months. That is a meaningful maintenance warning despite the package having released four times in the last 12 months.
The linked repository has no security policy. This reduces vulnerability-reporting transparency for an authentication module, although Dependabot and composer-audit provide some compensating security tooling.
All 24 analyzed action references are unpinned, and one workflow grants top-level write permissions; no untrusted trigger or audit finding was reported. The repository is not exposed to the most serious workflow risks, but its build inputs are harder to control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
web-auth/cose-lib Version ~4.4 | — | — |
simplesamlphp/assert Version ~2.0 | — | — |
spomky-labs/cbor-php Version ~3.2 | — | — |
symfony/http-foundation Version ~7.4 | — | — |
spomky-labs/pki-framework Version ~1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.