58%
Total Score
38
100
79
75
The package has 11 releases, but none in the last 12 months and its latest release was over three years ago, indicating likely dormancy.
There were no commits and no active maintainers during the measured three-month period, reinforcing the evidence that development has stopped.
Only one registry account has publish access, leaving limited visible publishing redundancy. This is a caution rather than a severe risk because repository activity is assessed separately.
The repository is owned by an individual account rather than an organization, so there is no provided evidence of organizational maintenance capacity to offset the single-maintainer profile.
There are no open issues or pull requests, but there was also no recent issue or pull-request activity; this provides little evidence of active maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/oauth2-client Version ^2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.