68%
Total Score
caution
Usable with caveats: one active contributor and a repository/name mismatch weaken confidence despite regular releases.
One contributor made 100% of the recent commits. With a user-owned project rather than organization backing, the package has limited visible handoff capacity.
Only one commit was recorded in the last 3 months, so maintenance is currently active but light. This is a modest concern when combined with the concentrated contributor base.
The repository name does not match the package name, and no README mention was collected. Although a name mismatch can occur with subpackages, the missing package reference makes ownership less transparent.
The repository has no security policy. For an OAuth integration library, this leaves vulnerability-reporting and response expectations less clear.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.0|^7.0 | — | — |
symfony/security-bundle Version ^5.4|^6.0|^7.0 | — | — |
symfony/framework-bundle Version ^5.4|^6.4|^7.0 | — | — |
symfony/options-resolver Version ^5.4|^6.4|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.