The package is clearly licensed and its repository matches the package name. Its tiny, undocumented artifact offers little evidence of current support, so pinning it carries long-term maintenance risk.
38%
Total Score
0
71
67
Only three releases were published, all within a few days in May 2020, followed by roughly six years with no release. This is strong evidence of abandonment risk.
The repository had zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no current maintenance capacity.
The artifact contains only ten files, mostly migration files plus the manifest and license, leaving little visible implementation or documentation context for consumers.
The package has no README, tests, or changelog, and the repository also reports no tests or changelog. The missing consumer documentation and validation are meaningful gaps for an OAuth2 integration package.
The repository has only two stars, zero forks, and one watcher. Popularity is supporting evidence rather than a verdict, but these numbers provide little evidence of broad review or community support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
itxq/think-phinx Version ^1.0 | — | — |
topthink/framework Version ^6.0 | — | — |
league/oauth2-server Version ^8.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.