The stable version, MIT licensing, and documented tests make the package understandable to adopt. Its source repository is not archived, but it has had no recent maintenance or security-policy coverage. Pinning this obsolete release would leave you without an active maintenance path.
18%
Total Score
50
67
50
Packagist marks the entire package as abandoned, with no replacement specified. That is a direct warning against taking a new dependency on this release.
The latest release was published in April 2018, with no releases in the following 12 months of the observed history; this indicates roughly eight years without release maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and weak evidence of ongoing maintenance.
No security policy was found in the linked repository, leaving vulnerability reporting and response expectations unclear for an OAuth integration package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dukt/oauth2-vimeo Version ^2.0 | — | — |
dukt/oauth2-google Version ^2.0 | — | — |
composer/installers Version ~1.0 | — | — |
league/oauth1-client Version ^1.7 | — | — |
league/oauth2-client Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.