The package is clearly licensed and documents installation and configuration well. Organization backing and release notes add useful context, but the small repository footprint and absent recent activity limit confidence.
57%
Total Score
75
83
67
The package has had no release in about three years, with zero releases in the last 12 months; its earlier five-release history provides some evidence of prior maintenance but not current activity.
There were no commits or active maintainers in the past three months, consistent with the long release gap and indicating a meaningful abandonment risk.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Version 0.1.3 is not marked prerelease, but the 0.x major line indicates a still-developing API and adds some adoption risk.
The single workflow was fully analyzed with no dangerous findings, but its only action reference is unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fof/oauth Version ^1.3 | — | — |
flarum/core Version ^1.2.0 | — | — |
firebase/php-jwt Version 6.5.0 | — | — |
patrickbussmann/oauth2-apple Version ^0.2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.