The package includes a README, tests, a matching source repository, and only two runtime dependencies. Its maintenance evidence is very weak, with no activity since 2015 and no security policy or scanning support, so pinning this old release carries substantial abandonment risk.
38%
Total Score
33
100
64
83
This is the package's only release, published over 11 years ago, with no releases in the last 12 months. That gives little evidence of ongoing maintenance or compatibility work.
There were zero commits and zero active maintainers in the last three months, consistent with the package's long absence of releases and indicating inactive maintenance.
The registry lists one maintainer. That can be normal for a small package, but it provides little visible resilience if the sole publisher becomes unavailable.
There has been no recent issue or pull-request activity, and one issue remains open. This is supporting evidence of a dormant project rather than a standalone severe risk.
Composer build tooling is present, but no security scanning tools were detected. The tooling supports reproducible package work but offers limited additional security assurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/oauth2-client Version >=0.10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.