Its README, tests, and changelog make the code easier to inspect, and the artifact carries an MIT license. A single runtime dependency and no install scripts reduce integration surprises, but they do not offset the maintenance concern.
38%
Total Score
100
64
75
The package has had no releases in the last 12 months; its latest release was in April 2016 despite being nearly 11 years old. This is strong evidence of abandonment risk.
The repository has zero stars and forks and only two watchers. Popularity is not decisive, but these counters provide little supporting evidence of active community use.
The repository is not archived, which avoids the strongest abandonment signal, but its last push was in April 2016 and does not compensate for the inactive release history.
The linked repository has no security policy. This is a transparency and maintenance gap, though it is less severe than the long period without releases.
The assessed version is still v0.0.10-alpha, and all recent releases are prereleases. Consumers should not expect a stable API or mature release process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/oauth2-client Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.