Package Health

web-auth/webauthn-lib

This is a mature, actively published package with 126 releases since 2019, 12 releases in the last 12 months, a stable non-prerelease version, a valid MIT license, an unarchived repository, and clear organization ownership with the repository matching and documenting the package. However, the linked repository shows no commits or active maintainers in the last 3 months despite the recent release, and neither the artifact nor repository reports tests or a changelog; for a security-sensitive WebAuthn library, these reduce confidence in ongoing validation and transparency. The repository also lacks security scanning and a security policy, while its workflow does not declare top-level token permissions. It is usable, but dependency adoption should include additional review and monitoring for maintenance continuity.

Latest 5.3.9PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Are you affected? Scan for Free

Health Score Breakdown

Dependency profilecaution

The package has 17 runtime dependencies, including cryptographic, serialization, and framework components. This is a meaningful dependency surface to monitor, but the signal does not show an excessive or clearly anomalous profile on its own.

Package scaffoldingcaution

The artifact has no README, tests, or changelog, and the repository also reports no tests or changelog. For a security-sensitive library, the absence of repository tests and release-history documentation is a genuine maintenance and transparency gap.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months. This conflicts with the strong release history and same-day push, but still indicates a recent collapse in observable development activity that warrants caution.

Repo issue activitycaution

There were no new issues or pull requests in the last month and no merged pull requests; this is neutral to mildly concerning, but the open-issue count is unknown and the signal alone does not establish abandonment.

Repo toolingcaution

Composer is used as the build tool, supporting reproducible ecosystem-native packaging, but no security scanning tools are configured; for authentication code, that is a meaningful hygiene gap.

Vulnerabilities

TitleVersionsSeverity
CVE-2024-39912
web-auth/webauthn-lib is vulnerable to Observable Response Discrepancy in versions 4.5.0 - 4.9.0.
4.5.0 - 4.9.0
Medium

Package versions

Maintainers

Florent Morselli
All contributors

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0|^2.0|^3.0
psr/clock
Version ^1.0
symfony/uid
Version ^6.4|^7.0|^8.0
symfony/clock
Version ^6.4|^7.0|^8.0
web-auth/cose-lib
Version ^4.8

Weekly Downloads

Info

Last Published
10 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform