The MIT license, extensive README, security policy, and exact repository match make the package transparent. Its single maintainer and tiny community offer little resilience if fixes are needed.
45%
Total Score
50
80
100
Only one registry maintainer is listed, so publishing and maintenance capacity are concentrated in a single person. The linked repository is also user-owned rather than organization-backed, providing no visible resilience against maintainer unavailability.
The package has had no releases in the last 12 months, and its latest release was on November 14, 2023—about two years and ten months ago. The 17-release initial history shows early activity but does not offset the prolonged gap.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating that fixes may not arrive promptly.
The repository has one star, zero forks, and one watcher, providing little evidence of a broad user or contributor community to help identify and address problems.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bshaffer/oauth2-server-php Version ^v1.14.0 | — | — |
bertugfahriozer/ci4commonmodel Version ^1.1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.