Package Health

simplesamlphp/xml-security

The documentation, tests, changelog, and security tooling support dependable integration. Organization backing and recent releases help offset the concentrated contributor activity, while workflow hygiene remains a concern.

Latest v3.1.0PackagistPackagist

74%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Are you affected? Scan for Free

Health Score Breakdown

Security policycaution

No SECURITY.md or equivalent security policy was found in the repository. For a library implementing XML signatures and encryption, this is a meaningful transparency gap.

Workflow auditcaution

All 23 analyzed action references are unpinned, and the audit found two high-confidence medium-severity secrets-inherit findings in php.yml. One workflow also has top-level write permissions, so workflow supply-chain hygiene lowers confidence in the release process.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-32600
simplesamlphp/xml-security is vulnerable to Improper Validation of Integrity Check Value in versions 2.0.0 - 2.3.1 and 0.0.0 - 1.13.9.
0.0.0 - 1.13.92.0.0 - 2.3.1
High
CVE-2023-49087
simplesamlphp/xml-security is vulnerable to Insufficient Verification of Data Authenticity in versions 1.6.11 - 1.6.11.
1.6.11 - 1.6.11
High

Package versions

Maintainers

Jaime Perez Crespo
Tim van Dijen

Direct Dependencies

DependencyLast ReleaseScore
psr/http-client
Version ^1.0
—
—
psr/http-factory
Version ^1.0
—
—
simplesamlphp/assert
Version ~3.0
—
—
simplesamlphp/xml-common
Version ~3.0
—
—

Weekly Downloads

Info

Last Published
12 hours ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform