It has a clear MIT license, a usable README, and a single focused runtime dependency. There are no tests, changelog, security policy, or security scanning tools, which leaves maintenance quality and review practices unclear.
42%
Total Score
100
58
50
The package has only one release, published about nine years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk, despite the package not being deprecated.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no community signal to compensate for the long maintenance gap.
Composer is used for the build, but the repository has no security scanning tools. For a package handling authentication integration, that leaves security and maintenance checks less transparent.
The repository is not archived, which keeps it technically available, but it was last pushed about nine years ago and therefore does not offset the stale release history.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, although it is secondary to the much stronger evidence of stale maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2-authclient Version ~2.0@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.