Risky to adopt: the release has received no updates for more than six years, with no recent commit or issue activity. It is clearly documented, licensed, and not deprecated, but maintenance appears effectively abandoned.
42%
Total Score
33
50
78
75
The package has had no release in more than six years, despite five releases shortly after its first publication. This is strong evidence of abandonment for an OAuth integration package that may need compatibility and dependency updates.
There have been zero commits and zero active maintainers in the last three months. Given that the repository last changed in June 2020, this is the strongest evidence that the project is effectively abandoned.
There are three runtime dependencies, including the framework, HTTP client, and WeChat integration library. This is a manageable dependency surface, though the old release means compatibility of those dependencies should be checked separately.
The repository is owned by an individual user rather than an organization, so the single registry maintainer and lack of recent activity provide limited backing capacity.
Six issues remain open, with no new or closed issues and no pull-request activity in the last month. Combined with the old last push, this indicates unresolved maintenance needs.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
overtrue/wechat Version ^4.0 | — | — |
guzzlehttp/guzzle Version >=6.0 | — | — |
encore/laravel-admin Version >=1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.