Configuration and symfony services for ekapusta/oauth2-esia.
55%
Total Score
caution
Usable with caveats: no release or commit activity since September 2020 raises abandonment risk.
The package has had 4 releases since May 2018, but its latest release was in September 2020 and there were no releases in the last 12 months. This long gap materially raises abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the multi-year release gap. The repository is not archived, but there is no observed recent maintenance.
There were no new or closed issues or pull requests in the last month, and no open issues or pull requests. This is consistent with a dormant project, although it does not by itself prove abandonment.
The project uses Composer build tooling, which fits the package ecosystem, but no security scanning tools were detected. The missing automated security coverage is a modest maintenance and transparency gap.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear. This is a transparency gap, though the package's small scope and visible source provide some compensation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^2.8 || ^3 || ^4 | — | — |
symfony/http-kernel Version ^2.8 || ^3 || ^4 | — | — |
ekapusta/oauth2-esia Version ^1.4 | — | — |
symfony/dependency-injection Version ^2.8 || ^3 || ^4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.