The package is licensed, documented, and backed by strong automated security and workflow checks. Its source activity is mixed, with many merged pull requests but no commits in three months, and the repository does not clearly identify the package.
65%
Total Score
75
88
75
There have been no registry releases in the last 12 months, and version 3.0.1 was published about 15 months ago. This weakens confidence in ongoing release maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. This is a meaningful maintenance concern, even though recent pull-request activity provides some counterevidence.
The repository name does not match the package name and its README does not mention the package. That makes package ownership and publication provenance less transparent.
The repository has no security policy. For an authentication plugin, the absence of a documented vulnerability-reporting path is a transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^2.0 | — | — |
wildwolf/yubico-otp Version ^4.0.1 | — | — |
wildwolf/singleton-trait Version ^1.0 | — | — |
wildwolf/wp-request-context Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.