The package includes tests, a clear README, and only one runtime dependency. Its source is small and transparent, but this old release leaves substantial compatibility and abandonment risk for new projects.
38%
Total Score
38
100
69
88
Only two releases were published, both in December 2020, with no releases in the last 12 months; the long silence is strong abandonment evidence.
There were no commits or active maintainers in the last three months, consistent with the multi-year release gap and materially increasing abandonment risk.
Registry publishing is controlled by one maintainer, leaving a thin ownership base and increasing continuity risk for an already inactive project.
The repository is owned by an individual account rather than an organization, so the single-maintainer concern is not offset by visible organizational backing.
There has been no recent issue or pull request activity, with one issue still open; this provides no evidence of active support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/oauth2-client Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.