Package Health

yard/samlbase

The package has a clear README and an organization-backed repository, but it lacks a security policy and automated security scanning. The workflow also inherits secrets and uses its only action without pinning, so pin this version only if its stable behavior fits your needs.

Latest v1.7.0PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

Only 2 releases exist, with no release in the last 12 months; the latest registry release was about 19 months ago. This is meaningful evidence of slow release maintenance for a library dependency.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although it was pushed more recently according to repository status, current observed development activity remains absent.

Repo toolingcaution

Composer and Phing are used for builds, but no security-scanning tooling is present. That is a modest concern for a package handling signing, encryption, and identity assertions.

Security policycaution

No repository security policy was found. For a SAML security library, this is a transparency gap because users benefit from clear vulnerability reporting and response guidance.

Workflow auditcaution

The single analyzed workflow has a high-confidence medium-severity secrets-inherit finding and its only action is unpinned. The workflow has no untrusted checkout or script-injection path, which limits the severity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ron van der Molen

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.4
—
—
guzzlehttp/guzzle
Version ^7.5
—
—
robrichards/xmlseclibs
Version ~3.1.0
—
—
symfony/dependency-injection
Version ^5.4 || ^6.4
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform