The package offers almost no consumer documentation, has no repository tests, and lacks a security policy. The linked repository had no commits in the last three months and does not identify or mention this package, despite a recent release and organizational ownership.
46%
Total Score
75
75
75
The repository name does not match the package and its README does not mention it, raising concern that the source repository may not belong to this package. Organizational ownership provides some context but does not resolve the mismatch.
The artifact has a README, but it is only 12 characters and contains no usage guidance; the repository also has no tests or changelog. Missing tests and changelogs are normal packaging practice, but the nearly empty README weakens consumer transparency.
The repository recorded zero commits and zero active maintainers in the last three months, which is a maintenance concern. A release and repository push occurred recently, so this indicates limited recent development rather than clear abandonment.
Composer is used as the build tool, which is appropriate, but no security-scanning tools are configured. That reduces evidence of ongoing supply-chain hygiene.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a hygiene and transparency gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
thenetworg/oauth2-azure Version dev-master | — | — |
socialiteproviders/microsoft Version ^4.0 | — | — |
socialiteproviders/microsoft-azure Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.