Usable with caveats: the package is clearly identified, licensed, tested, and has a clean dependency profile, but its last release was nearly nine years ago and repository activity stopped over five years ago. Depend on it only if the stable, narrow integration still meets your needs and you can maintain it yourself.
52%
Total Score
50
100
72
88
The package has five releases, but none in the last 12 months; version 1.1.1 was released nearly nine years ago. This is a substantial maintenance and abandonment concern for a library dependency.
There were no commits or active maintainers in the last three months, consistent with a project that has been inactive for years. This materially raises the risk that defects or compatibility changes will not be addressed.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these very low figures provide little external evidence of ongoing use or review.
Composer is used for builds, but no security scanning tools are configured. The missing scanning is a transparency gap, although this small package has no reported workflow activity to expose.
The linked repository is not archived, but it was last pushed over five years ago. The non-archived status is reassuring, though it does not offset the lack of recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/oauth2-client Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.