Package Health

dilab/envato-oauth2-provider

The package includes a README, tests, a matching source repository, and only two runtime dependencies. Its maintenance evidence is very weak, with no activity since 2015 and no security policy or scanning support, so pinning this old release carries substantial abandonment risk.

Latest 0.1.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

64

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

This is the package's only release, published over 11 years ago, with no releases in the last 12 months. That gives little evidence of ongoing maintenance or compatibility work.

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months, consistent with the package's long absence of releases and indicating inactive maintenance.

Maintainerscaution

The registry lists one maintainer. That can be normal for a small package, but it provides little visible resilience if the sole publisher becomes unavailable.

Repo issue activitycaution

There has been no recent issue or pull-request activity, and one issue remains open. This is supporting evidence of a dormant project rather than a standalone severe risk.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The tooling supports reproducible package work but offers limited additional security assurance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

xu ding

Direct Dependencies

DependencyLast ReleaseScore
league/oauth2-client
Version >=0.10.0

Weekly Downloads

Info

Last Published
11 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform