Package Health

in2code/typo3-oauth2-client-fork

The license declaration conflicts with the GPL-3.0 file, and all five workflow actions are unpinned. A high-confidence template-injection finding and missing security policy add transparency and release-process concerns.

Latest 3.0.1PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The latest release was in April 2024, about 2 years and 5 months ago, with no releases in the last 12 months. This indicates a materially inactive release line.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the lack of recent maintenance capacity.

Licensecaution

The manifest declares GPL-2.0-or-later, while the detected LICENSE file is GPL-3.0. The package is licensed, but the declaration and license text do not align.

Repo package mentioncaution

The repository name does not match the package and its README does not mention this package, so the linked source may not clearly belong to this release.

Security policycaution

The repository has no security policy, leaving reporting and response expectations undocumented for an authentication-related extension.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

waldhacker

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version *
—
—
typo3/cms-core
Version ^11.5@dev || ^12.4@dev
—
—
typo3/cms-fluid
Version ^11.5@dev || ^12.4@dev
—
—
typo3/cms-setup
Version ^11.5@dev || ^12.4@dev
—
—
typo3/cms-backend
Version ^11.5@dev || ^12.4@dev
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform