It has a clear license, tests, and a useful README, with a small organization-backed project and no install scripts. Security scanning is absent, so maintenance confidence is limited.
58%
Total Score
67
100
75
83
The package has six releases since November 2018, but none in the last 12 months and the latest release was published in January 2021. This is a meaningful maintenance concern for a dependency.
There were zero commits and zero active maintainers in the last three months, with the repository last pushed in January 2021. This strongly limits evidence of current maintenance.
There are no open issues or pull requests, and no recent issue or pull request activity. The clean tracker is positive, but alongside the absent commits it is more consistent with a quiet project than active maintenance.
The repository has only two stars, one fork, and no watchers. Popularity is supporting evidence rather than a verdict, but these counts provide little external evidence of maturity or ongoing community support.
The repository uses Composer, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than proof of a vulnerability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/oauth2-client Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.