The package is clearly documented, MIT-licensed, and published from an organization-backed repository without install-time scripts. Recent repository activity has stopped, and the project has no security policy or scanning tools, so maintenance and transparency need attention.
67%
Total Score
75
100
89
75
There were 0 commits and 0 active maintainers in the last 3 months. The recent release partly compensates for this, but the current lack of observed development lowers confidence in ongoing maintenance.
The repository has 1 star, 0 forks, and 2 watchers, indicating a very small user footprint. Popularity is only supporting evidence, so this is a minor concern rather than a verdict.
Composer build tooling is present, but no security scanning tools were detected. For a package handling OAuth integration, that is a modest security-process gap.
The repository has no security policy. This weakens vulnerability-reporting transparency, though it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
flipboxfactory/patron Version ^5.0 | — | — |
flipboxfactory/craft-salesforce Version ^5.0 | — | — |
flipboxdigital/oauth2-salesforce Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.