The small, tested codebase has a clear MIT license, matching repository, and organization backing. Its single 2018 release and absent recent commits leave maintenance and compatibility uncertain.
38%
Total Score
50
100
63
88
This package has only one release, published in July 2018, with no releases in the past 12 months. That long period without a new release is strong evidence of abandonment risk.
There were no commits and no active maintainers in the last three months, consistent with the repository having been dormant since 2018. This materially raises maintenance and abandonment risk.
The repository has zero stars and zero forks, with six watchers. Low adoption is supporting evidence of limited community validation, though it is not decisive for a small package.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than proof of unsafe code.
The linked repository is not archived, which avoids an explicit abandonment marker. However, its last push was in July 2018, so this does not offset the stale activity evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/oauth2-client Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.