Its MIT license, clear README, matching repository, and stable release make the package easy to inspect. The small dependency base is manageable, but missing tests, security scanning, and a security policy reduce assurance for an OAuth integration.
42%
Total Score
25
50
79
75
The package has only one release, published in November 2018, with no releases in the last 12 months. This is strong evidence of abandonment for a package integrating changing third-party OAuth services.
The repository recorded zero commits and zero active maintainers over the past three months, consistent with the package having received no maintenance since November 2018.
Five runtime dependencies, including several OAuth client libraries and Guzzle, create some maintenance exposure because their compatibility may evolve. The dependency count is still manageable rather than excessive.
Only one registry account has publishing access. Because the repository is user-owned and recent activity is absent, there is limited visible continuity if that maintainer does not return.
Composer build tooling is present, but no security scanning tools were detected. That is a modest transparency and maintenance gap for a package handling OAuth credentials.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.0 | — | — |
league/oauth2-client Version ^2.0 | — | — |
league/oauth2-google Version dev-master | — | — |
hayageek/oauth2-yahoo Version dev-master | — | — |
microsoft/microsoft-graph Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.