The MIT license, matching repository, and release notes make its origin and basic use easier to assess. Its small contributor footprint and lack of security tooling provide little evidence of ongoing support.
38%
Total Score
50
75
83
This is the package's only release, published over 12 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk despite the absence of registry deprecation.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the package's long release gap and providing no evidence of current maintenance.
There were no new or merged issues or pull requests in the last month. While a quiet issue tracker can be normal for a small package, here it reinforces the absence of recent project activity.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools are configured. This is a maintenance and transparency gap rather than evidence of maliciousness.
The repository has no security policy, reducing transparency about vulnerability reporting and response. This matters more given the lack of recent maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hrevert/ht-oauth-client Version 0.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.