The package is small, clearly MIT-licensed, documented, and has no install-time scripts. Its limited source tree and absent security policy provide little evidence of ongoing maintenance or operational maturity.
43%
Total Score
0
69
75
The package has only two releases, with the latest published about 9 years ago and no releases in the last 12 months. This is strong evidence of abandonment risk despite the package's age.
There were no commits and no active maintainers in the last 3 months. Combined with the old last push and release history, this materially raises abandonment risk.
The repository name does not match the package name and its README does not mention the package. A sub-package explanation is not provided by the collected evidence, so package provenance is less clear.
The repository uses Composer, providing basic build tooling, but no security scanning tools were detected. This is a modest transparency and maintenance gap for a dependency handling authentication-related functionality.
The repository is not archived, which is a modest compensating signal, but its last push was about 9 years ago and does not demonstrate current maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.