The package is licensed, tested, documented, and has a small, clear dependency set. Its single-user ownership, absent security scanning, and unpinned workflow actions leave more maintenance and build-integrity risk than a mature dependency should have.
66%
Total Score
50
100
83
75
Only one registry account has publish access. That is not proof of poor maintenance, but it leaves little publishing redundancy for a user-owned project.
The registry namespace and repository owner match, supporting that the linked repository belongs to this package; the owner is an individual rather than an organization, so there is limited visible backing.
The package has existed since 2020 with six releases, but it had no releases in the collected 12-month period after the July 2025 release, indicating slow maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release-history gap and raising abandonment risk.
The repository has one star, no forks, and no watchers. Low adoption is only supporting evidence, but it provides little external maintenance signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/oauth2-client Version ^2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.