The package has had no release or repository commit activity for about 3 years, and its workflow uses an unpinned latest container image. Tests, release notes, licensing, and organization backing provide useful evidence of a real, structured project.
58%
Total Score
50
100
78
75
The repository recorded zero commits and zero active maintainers in the last 3 months, a strong sign that maintenance has stopped rather than merely slowed.
The package has 32 releases over about 8 years, but its latest release was in July 2023 and there were no releases in the following 12 months of the collected history. The long gap lowers confidence that current issues will be addressed.
There are 19 open issues and no issues or pull requests were closed or merged in the last month, indicating little visible recent project activity.
The repository has 9 stars and 8 forks, indicating a small user and contributor footprint. Popularity is supporting evidence only, so this modest level is a minor concern rather than a decisive risk.
Composer is used for builds, but no security scanning tool was detected. The missing scanning coverage is a hygiene gap, not evidence that the release is unsafe by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/core Version ^9.4 || ^10.0 | — | — |
drupal/simplesamlphp_auth Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.