It has a clear README, MIT licensing, focused runtime dependencies, and organization backing. The unpinned workflow actions and absent security policy add hygiene concerns, while the available release documentation does not offset the weak maintenance evidence.
38%
Total Score
50
100
79
50
Only two releases exist, and the latest was published in November 2022; there have been no releases in about 3 years and 10 months. This is strong evidence of abandonment risk for a package intended as an application extension.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap. No provided activity signal compensates for this lack of recent maintenance.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest process gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, especially for an extension handling OAuth credentials.
The single workflow was fully analyzed with no untrusted checkout or script-injection findings, but all 3 action references are unpinned. That leaves build inputs less reproducible and increases workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fof/oauth Version ^1.3 | — | — |
flarum/core Version ^1.3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.