Documentation, tests, and a matching repository make the package easier to assess. Organization backing, a clear MIT license, and no install-time scripts partly offset the aging maintenance picture.
58%
Total Score
67
100
89
83
The latest release was over four years ago, with no releases in the last 12 months. The package has a history of ten releases, but the long pause is a meaningful maintenance concern.
There were no commits and no active maintainers in the last three months. Combined with the old latest release, this supports a caution about current maintenance capacity.
There was no issue or pull-request activity in the last month, with one open issue. This is consistent with a quiet project but does not alone establish abandonment.
The repository uses Composer, but no security-scanning tools were detected. The missing scanning is a modest transparency and maintenance gap.
The repository has no security policy. That weakens vulnerability-reporting transparency, although it is not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/oauth2-client Version ^2.0 | — | — |
jakeasmith/http_build_url Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.