The MIT license, clear README, repository tests, and lack of install-time scripts make the package straightforward to inspect and integrate. However, it has had no release or commit activity since 2015, with only one maintainer and no security policy, so maintenance and abandonment risk are substantial.
35%
Total Score
0
100
75
75
The package has released only twice, with the latest release in 2015 and no releases in the last 12 months. This long period without published updates is strong evidence of abandonment risk.
The repository has had zero commits and zero active maintainers in the last three months, and its last push was in 2017. This confirms that the project is not receiving current maintenance.
The repository has one star, zero forks, and two watchers. Low popularity is only supporting evidence, but it provides little indication of an active user or contributor community.
The repository has no security policy. For an old OAuth-related library, this is a transparency gap because users have no documented process for reporting security issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/oauth2-client Version 0.9.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.