The package has clear MIT licensing and a small, understandable dependency footprint. Its source is archived and has had no commits or releases for more than six years, leaving this extension without active maintenance.
12%
Total Score
25
100
40
100
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk because the registry explicitly signals that the package should no longer be depended on.
Only two releases were published, with the latest more than seven years ago and none in the last 12 months. This indicates a long-standing lack of release maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. Together with its archived status, this confirms that development has stopped.
The linked repository is archived and was last pushed more than six years ago. Archived source cannot receive normal maintenance or fixes.
There has been no recent issue or pull-request activity. This is consistent with abandonment, although the absence of open issues alone would not be concerning for a mature project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^0.1.0-beta.8 | — | — |
sergey-sla/oauth2-vkontakte Version ^1.0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.