The documentation, tests, changelog, and security tooling support dependable integration. Organization backing and recent releases help offset the concentrated contributor activity, while workflow hygiene remains a concern.
74%
Total Score
100
100
67
No SECURITY.md or equivalent security policy was found in the repository. For a library implementing XML signatures and encryption, this is a meaningful transparency gap.
All 23 analyzed action references are unpinned, and the audit found two high-confidence medium-severity secrets-inherit findings in php.yml. One workflow also has top-level write permissions, so workflow supply-chain hygiene lowers confidence in the release process.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-32600 simplesamlphp/xml-security is vulnerable to Improper Validation of Integrity Check Value in versions 2.0.0 - 2.3.1 and 0.0.0 - 1.13.9. | 0.0.0 - 1.13.92.0.0 - 2.3.1 | High |
CVE-2023-49087 simplesamlphp/xml-security is vulnerable to Insufficient Verification of Data Authenticity in versions 1.6.11 - 1.6.11. | 1.6.11 - 1.6.11 | High |
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
simplesamlphp/assert Version ~3.0 | — | — |
simplesamlphp/xml-common Version ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.