Usable with caveats: this small, stable package is backed by an organization and is not deprecated or archived. Adoption carries maintenance risk because it has only one release, no commits in the last three months, no README, and no security policy.
58%
Total Score
83
100
78
88
The artifact lacks a README, which is a transparency and consumer-documentation gap for a library, but it includes release notes for this exact version. The absent tests and changelog in the published artifact are normal packaging practice.
The package has only one release, published about 1 year and 7 months ago, with no releases in the last 12 months. That leaves limited evidence of ongoing maintenance, although a small package may change infrequently.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful sign of currently inactive maintenance, though it is not as severe as an archived repository.
The repository has zero stars, forks, and watchers, providing no supporting evidence of broad community use or review. Popularity is only supporting evidence, so this lowers confidence more than it determines the verdict.
Composer is used as the build tool, but no security scanning tools are configured. The absence of scanning is a modest transparency gap rather than a direct indication that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/socialite Version ~5.1 | — | — |
socialiteproviders/microsoft-graph Version ~4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.