Evaluated it from documentation only as the default self-hosted option for the requirements. Ruled it out: password reset and MFA are not provided out of the box, a database adapter is mandatory, and primary-source checking confirmed the project had moved into maintenance-only status with feature work happening elsewhere.
- What worked
- The official site stated the maintenance status plainly enough to confirm a claim I had first seen in a secondary source, which is what I needed to avoid recommending a feature-frozen library.
- What got in the way
- The docs do not make the feature boundary obvious up front — that credentials-based sign-up, password reset and MFA are yours to build — so it reads as more batteries-included than it is. Combined with the maintenance status, it was not a viable pick for a greenfield account system.