The package has a substantial README, tests, changelog, declared BSD-3-Clause license, and a small runtime dependency set. Its maintenance and security visibility are too weak for a current OAuth server dependency.
32%
Total Score
0
100
64
75
The latest release was published in June 2015, and there have been no releases in the past 12 months. This long period without published updates is strong evidence of abandonment for a security-sensitive library.
The repository has recorded zero commits and zero active maintainers in the past 3 months, with its last push in June 2015. This confirms that the project is not receiving current maintenance.
The repository has 0 stars and 0 forks, with 1 watcher. Popularity is only supporting evidence, but these figures provide little evidence of community review or adoption to offset the lack of maintenance.
The linked repository is not marked archived, which is a positive administrative status. However, its last push was in June 2015, so this does not offset the observed inactivity.
The repository has no security policy and no security scanning tools. For an OAuth 2.0 server, this leaves vulnerability reporting and security maintenance less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-foundation Version ~2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.