The package is clearly documented, licensed, tested, and has a small dependency set. Its single-maintainer project has no security policy or automated security scanning, which increases the cost of relying on an aging OAuth implementation.
42%
Total Score
33
100
67
50
The latest release was published over seven years ago, and there have been no releases in the last 12 months. This is strong evidence of abandonment for a security-sensitive library, despite its earlier 13-release history.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the release gap and leaving little evidence of ongoing maintenance.
Only one registry account has publish access. That can be normal for a user-owned project, but it leaves a thin publishing and maintenance base when combined with the long period of inactivity.
There are six open issues and no issues or pull requests were opened or closed in the last month. This supports the broader picture of limited current project activity, but is not independently severe.
Composer build tooling is present, but no security-scanning tool was detected. For an OAuth server library, that is a meaningful hygiene gap, though it is less severe than the long maintenance pause.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ^2.0 | — | — |
jakeasmith/http_build_url Version >=1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.