The package has a clear README and an organization-backed repository, but it lacks a security policy and automated security scanning. The workflow also inherits secrets and uses its only action without pinning, so pin this version only if its stable behavior fits your needs.
60%
Total Score
75
86
67
Only 2 releases exist, with no release in the last 12 months; the latest registry release was about 19 months ago. This is meaningful evidence of slow release maintenance for a library dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although it was pushed more recently according to repository status, current observed development activity remains absent.
Composer and Phing are used for builds, but no security-scanning tooling is present. That is a modest concern for a package handling signing, encryption, and identity assertions.
No repository security policy was found. For a SAML security library, this is a transparency gap because users benefit from clear vulnerability reporting and response guidance.
The single analyzed workflow has a high-confidence medium-severity secrets-inherit finding and its only action is unpinned. The workflow has no untrusted checkout or script-injection path, which limits the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.4 | — | — |
guzzlehttp/guzzle Version ^7.5 | — | — |
robrichards/xmlseclibs Version ~3.1.0 | — | — |
symfony/dependency-injection Version ^5.4 || ^6.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.