The package includes tests, a changelog, a clear README, and a matching repository, but its last release and repository push were in 2018 with no recent commits. No security scanning or security policy is present, increasing the maintenance concern for an OAuth2 project.
38%
Total Score
0
50
71
75
The latest release was in November 2018, with no releases in the last 12 months and only five releases overall. This long period without published updates is a substantial abandonment concern.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap. The linked repository is not archived, but it shows no recent maintenance activity.
The package declares 12 runtime dependencies, including OAuth2, middleware, and framework components. This is a meaningful dependency surface for an old package, though the signal does not show that the dependencies are currently unsafe.
Composer is used as a build tool, showing basic project tooling, but no security scanning tools were detected. The missing security automation is a modest transparency and maintenance gap.
The repository has no security policy. For a package implementing OAuth2 handlers and authentication flows, that weakens vulnerability-reporting transparency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
jstormes/ezauth2 Version dev-master | — | — |
league/oauth2-client Version ^2.3 | — | — |
league/oauth2-server Version * | — | — |
psr7-sessions/storageless Version ^4.0 | — | — |
zendframework/zend-stdlib Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.