This is a mature, actively published package with 126 releases since 2019, 12 releases in the last 12 months, a stable non-prerelease version, a valid MIT license, an unarchived repository, and clear organization ownership with the repository matching and documenting the package. However, the linked repository shows no commits or active maintainers in the last 3 months despite the recent release, and neither the artifact nor repository reports tests or a changelog; for a security-sensitive WebAuthn library, these reduce confidence in ongoing validation and transparency. The repository also lacks security scanning and a security policy, while its workflow does not declare top-level token permissions. It is usable, but dependency adoption should include additional review and monitoring for maintenance continuity.
68%
Total Score
75
50
89
80
The package has 17 runtime dependencies, including cryptographic, serialization, and framework components. This is a meaningful dependency surface to monitor, but the signal does not show an excessive or clearly anomalous profile on its own.
The artifact has no README, tests, or changelog, and the repository also reports no tests or changelog. For a security-sensitive library, the absence of repository tests and release-history documentation is a genuine maintenance and transparency gap.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. This conflicts with the strong release history and same-day push, but still indicates a recent collapse in observable development activity that warrants caution.
There were no new issues or pull requests in the last month and no merged pull requests; this is neutral to mildly concerning, but the open-issue count is unknown and the signal alone does not establish abandonment.
Composer is used as the build tool, supporting reproducible ecosystem-native packaging, but no security scanning tools are configured; for authentication code, that is a meaningful hygiene gap.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-39912 web-auth/webauthn-lib is vulnerable to Observable Response Discrepancy in versions 4.5.0 - 4.9.0. | 4.5.0 - 4.9.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0|^2.0|^3.0 | — | — |
psr/clock Version ^1.0 | — | — |
symfony/uid Version ^6.4|^7.0|^8.0 | — | — |
symfony/clock Version ^6.4|^7.0|^8.0 | — | — |
web-auth/cose-lib Version ^4.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.