Nine commits in three months from two active contributors, with tests and a clear license, support ongoing maintenance. No security policy or repository security scanning leaves limited assurance for this OAuth-enabled integration.
68%
Total Score
100
83
75
The repository name does not match the package name and its README does not mention the package. That weakens provenance confidence because the linked repository may not clearly establish that it is the package's source.
The repository uses Composer and a build tool, but no security-scanning tool was detected. For an OAuth-enabled package handling content access, this leaves a meaningful assurance gap.
No repository security policy was found. This does not show a vulnerability, but it provides little guidance for reporting issues in a package that implements authentication and token handling.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
neos/neos Version ^9.1 | — | — |
php-mcp/server Version ^3.3 | — | — |
composer/semver Version ^3.0 | — | — |
guzzlehttp/guzzle Version ^7.4 | — | — |
league/oauth2-server Version ^8.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.