This is a healthy, actively maintained release with a strong recent release cadence, stable versioning, an unarchived repository, substantial tests and documentation, and clear package-to-repository linkage. The main concerns are heavy dependence on one contributor, the absence of a declared repository security policy, and incomplete GitHub Actions permission declarations; these warrant operational review but do not outweigh the evidence of active development and mature project scaffolding.
82%
Total Score
75
100
94
80
The repository is owned by the individual user HugoFara rather than an organization. This is compatible with the observed active development, but it provides less organizational maintenance redundancy and reinforces the bus-factor concern.
Although two contributors were active, one contributor made 147 of 148 recent commits, or about 99.3%. Because the repository owner is an individual rather than an organization, this concentration is a genuine maintenance-continuity caution.
Composer is used as a build tool, but no security-scanning tooling was detected. The absence of scanning is a hygiene gap, though it is partly mitigated by the repository's active maintenance and separate workflow analysis.
The repository has no SECURITY.md or other declared security policy. This reduces vulnerability-reporting transparency, though it is a governance gap rather than evidence of abandonment.
Seven of eight workflows lack top-level token permissions, and one workflow declares top-level write access; no workflows declare read-only permissions. This leaves GitHub Actions privilege boundaries less explicit than desirable and merits review.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phpmailer/phpmailer Version ^7.0 | — | — |
league/oauth2-google Version ^5.0 | — | — |
thenetworg/oauth2-azure Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.