Documentation and licensing are clear, and the repository still has tests and automated dependency scanning. The lack of recent commits and the project's stated search for maintainers make long-term fixes uncertain; pin this version if you adopt it.
51%
Total Score
50
75
67
The package declares Apache-2.0 and includes license files, but the artifact also detects BSD-3-Clause, which is not covered by the declaration. The release is licensed, though the licensing metadata is not fully aligned.
The artifact includes a README and this exact version has GitHub release notes; the source repository also has tests and a changelog. The README explicitly says the project is unmaintained and seeking active maintainers, which materially increases abandonment risk.
The package has had no release in the last 12 months, and its latest release was about 14 months ago. This is a meaningful maintenance concern for an authentication library.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. That supports the project's statement that it is not actively maintained.
The linked repository has no security policy. For an authentication library, the absence of a documented vulnerability-reporting process is a real transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.