The artifact is small, documented, licensed, and easy to install, with a matching organization-owned repository. Its release notes document the shipped change, but the available evidence provides little ongoing maintenance or security oversight.
45%
Total Score
50
100
71
50
The latest release was over six years ago, with no releases in the last 12 months. That long gap is a substantial abandonment concern despite a previously regular release history.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release hiatus and suggesting no current maintenance capacity.
Composer is used for the build, but no security scanning tools are configured. That is a meaningful hygiene gap for a package handling SSO authentication.
The linked repository has no security policy. For an authentication library, this weakens transparency around vulnerability reporting and response.
Version 0.2.0 is not a stable major release, which signals a less mature API; the explicit release notes and long-standing publication history partly offset that concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.