The MIT license and matching repository make the package transparent to inspect. Its small dependency set and lack of install scripts reduce adoption friction, but the project offers little evidence of ongoing care.
42%
Total Score
50
100
61
75
The latest release was about three years ago, with no releases in the last 12 months; the five-release history shows the project has effectively stalled.
There were zero commits and zero active maintainers in the last three months, reinforcing the evidence that maintenance has stopped.
The artifact has no README, tests, or changelog, while the repository also has no tests or changelog. The GitHub release for this version is a small positive, but the missing consumer documentation and verification remain concerns.
There are no open issues or pull requests and no recent activity; while this may reflect a small project, it provides no sign of active maintenance.
The repository has zero stars and forks and only one watcher, offering little evidence of community use or external review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/oauth2-client Version ^2.6 | — | — |
thenetworg/oauth2-azure Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.