Testing, release notes, and licensing are in place. Maintenance has stopped for about 18 months, issue work is also inactive, and the workflow uses unpinned container images.
61%
Total Score
50
100
86
75
The package has a long history and 29 releases, but its latest release was about 18 months ago with no releases in the last 12 months. This indicates materially slowed maintenance for a mature library.
The repository recorded zero commits and zero active maintainers over the last three months. Combined with the older latest release, this is evidence of stalled maintenance.
There were no new or closed issues and no new or merged pull requests in the last month, while 255 issues and 33 pull requests remain open. This suggests limited current project attention.
Composer build tooling is present, but no security-scanning tool was detected. For an OAuth2 security-sensitive library, that is a meaningful hygiene gap, though it is not proof of a vulnerability.
The repository has no security policy. For authentication and authorization software, the absence of a documented vulnerability-reporting process reduces transparency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.