The README, tests, MIT licensing, and small runtime dependency set make the package straightforward to evaluate. Its very short history and narrow maintenance base warrant checking for a newer release before committing to it.
62%
Total Score
50
100
88
83
The repository owner is recorded as a GitHub user rather than an organization. Combined with the single-contributor activity, this provides limited evidence of institutional maintenance capacity.
This is a young package, released once 59 days ago, with no subsequent releases. That limits evidence of maintenance maturity, though the short age makes the lack of a longer history less conclusive.
One contributor holds 100% of the two recent commits. The project therefore has a high handoff risk if that maintainer stops working on it.
Only two commits were recorded in the last three months, all from one active maintainer. This is evidence of a thin maintenance base and limited ongoing development.
Composer is used for builds, but no security scanning tools were detected. That is a modest transparency and maintenance gap for a package handling OAuth2/OIDC functionality.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.