The README, tests, matching repository, and MIT license make the package understandable and straightforward to integrate. Maintenance appears weak: no release since January 2020 and no commits in the last three months, despite the repository remaining active rather than archived.
61%
Total Score
50
81
50
The package has had no release in about 6 years and none in the last 12 months, which materially raises abandonment and compatibility risk. Its 11-release history shows prior development but does not offset the long period of release inactivity.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, indicating no current maintenance activity. This is a significant concern for a library whose documented supported PHP versions are old.
The repository has 1 star and 1 fork, indicating limited external adoption and review. Popularity is supporting evidence only, so this modestly reduces confidence rather than determining the health verdict.
The repository uses Composer, but no security-scanning tool was detected. The missing scanner is a hygiene gap rather than a severe risk, especially given the otherwise small dependency profile.
No security policy was found, leaving vulnerability-reporting expectations unclear. This lowers transparency somewhat but is not by itself evidence that the package is unsafe to depend on.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version * | — | — |
league/oauth2-client Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.