Package Health

cfreear/oauth2-mailchimp

It has a clear MIT license, a small dependency footprint, tests, and a repository that matches the package. The single-maintainer project has had no release or commit activity for over three years, so future compatibility support is uncertain.

Latest 2.1.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Maintainerscaution

One registry maintainer publishes the package, which leaves a thin visible publishing base for a project needing future fixes. The matching repository and existing tests provide some compensating transparency.

Release historycaution

The package has only three releases and none in the last 12 months; its latest release was over three years ago. This is a meaningful maintenance concern, though the stable 2.1.0 release may suit an unchanged integration.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers during the last three months, consistent with the long release gap. The repository is not archived, but current maintenance capacity is not demonstrated.

Repo popularitycaution

The repository has zero stars and forks and one watcher, providing little community evidence or backup for maintenance. Low popularity is supporting evidence rather than a standalone reason to reject a small, stable package.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tooling is reported. The missing scanner is a hygiene gap, while the build configuration supports reproducible project maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Christian Freear

Direct Dependencies

DependencyLast ReleaseScore
league/oauth2-client
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform