The release includes a README, tests, a license, and security scanning in its repository. Its workflows leave all 23 action references unpinned, adding avoidable maintenance risk.
15%
Total Score
64
50
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency on the package.
The linked repository is archived, so its source is no longer actively maintained; it was last pushed over two years ago. This makes fixes and compatibility updates unlikely.
The package has had no release in over three years, despite 13 releases since February 2022. That inactivity reinforces the abandonment evidence from the archived repository.
The repository has no security policy, leaving the process for reporting and handling vulnerabilities undocumented. Existing security scanning helps, but does not replace a disclosure process.
All 23 analyzed action references are unpinned, creating avoidable build reproducibility and dependency-substitution risk. The audit found no untrusted checkouts, script injection, or high-severity findings, which limits the impact to caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.5.0 | — | — |
simplesamlphp/assert Version ^0.8.0 | — | — |
simplesamlphp/simplesamlphp Version ^2.0.0-rc2 | — | — |
giggsey/libphonenumber-for-php-lite Version ^8.13.4 | — | — |
simplesamlphp/composer-module-installer Version ^1.3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.