The linked repository is correctly identified, licensed, and not archived, with a readable package and no install-time scripts. Its small popularity, absent security policy, and unpinned workflow actions add little confidence for a new dependency.
15%
Total Score
50
64
50
Packagist marks the entire package as abandoned and names fof/passport as its replacement. This is a direct warning against taking a new dependency on this package.
Only two releases exist, with the latest published on November 5, 2018 and none in the last 12 months. That release history indicates a long-unmaintained registry artifact.
The repository recorded zero commits and zero active maintainers in the last three months. This provides no evidence of current maintenance capacity despite the repository remaining unarchived.
The repository has no security policy. That weakens vulnerability-reporting transparency, although it is secondary to the package's abandonment status.
The assessed release is 0.2.0-beta, and all recent releases are prereleases. Combined with the package's age, this signals an unfinished dependency rather than a stable release line.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^0.1.0-beta.8 | — | — |
league/oauth2-client Version ^2.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.