Usable with caveats: the release is clearly packaged, licensed, tested, and actively developed, but it is only 6 days old and all 27 recent commits come from one individual. The lack of security scanning and a security policy adds transparency risk for a session-management library.
68%
Total Score
80
100
83
90
Only one registry account has publishing access. That is consistent with a small project, but it leaves limited visible publishing continuity if the maintainer becomes unavailable.
The package is only 6 days old and has two releases, so its active release cadence is encouraging but provides little evidence of long-term maintenance or maturity.
All 27 recent commits came from one contributor, creating a high bus-factor risk. The repository is user-owned rather than organization-owned, so no provided backing signal compensates for that concentration.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this lowers external validation but is not by itself a major health failure for a newly released package.
Composer build tooling is present, but no security-scanning tooling was detected. For a library handling authentication sessions, that is a meaningful transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
stougeiro/session-contract Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.