Usable with caveats: the package is licensed, documented, tested, and not deprecated, but it has had no release or repository activity for about 3 years 5 months. Its very small project footprint and lack of security policy also make long-term maintenance uncertain.
55%
Total Score
50
100
71
50
Only two releases were published, with none in the last 12 months; the latest release was about 3 years 5 months ago. That long release gap is a meaningful maintenance concern for an OAuth integration.
The repository recorded zero commits and zero active maintainers during the last 3 months, consistent with the long period since the last push and indicating likely abandonment risk.
There are no open issues or pull requests and no recent issue activity. This is not itself harmful, but it provides no evidence of an active support process.
The repository name matches the package, which supports the link, but the README does not mention the package name. This creates a small ownership and package-to-repository transparency concern.
Composer build tooling is present, but no security-scanning tools were detected. For a package handling OAuth credentials and tokens, that is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^3.9 | — | — |
guzzlehttp/guzzle Version ^7.5 | — | — |
symfony/polyfill-php80 Version ^1.27 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.