The last release was over eight years ago, with no recent commits or active maintainers. It has tests, a README, a matching repository, and a valid MIT license, but the registry marks the package abandoned and names a replacement.
20%
Total Score
25
63
75
Packagist marks the entire package as abandoned and provides api-skeletons/oauth2-doctrine-identity as a replacement, which is a severe adoption concern.
The package has had no releases in the last 12 months, and its latest release was published over eight years ago; the earlier regular cadence does not compensate for the prolonged gap.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with long-term abandonment.
The repository is owned by the API-Skeletons organization, providing project backing context, but observed release and commit inactivity still indicates that the package is not maintained.
Composer is used as a build tool, but no security scanning tools are reported; this is a secondary transparency gap beside the much stronger abandonment evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gianarb/angry Version ^0.1 | — | — |
bshaffer/oauth2-server-php Version ^1.10 | — | — |
api-skeletons/zf-oauth2-doctrine Version ^3.1 | — | — |
container-interop/container-interop Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.