Package Health

markocupic/contao-oauth2-client

Maintenance depends on one contributor, and the repository has no security policy while all four workflow actions are unpinned. The README, repository tests, recent releases, and lack of deprecation provide useful reassurance.

Latest 1.2.5PackagistPackagist

66%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Maintainerscaution

Only one account has registry publishing access. This is a modest publishing and continuity concern for a user-owned project, although registry access does not by itself measure actual development activity.

Project backingcaution

The repository is owned by an individual rather than an organization, so the single-contributor and single-maintainer concentration represents a genuine continuity concern.

Repo bus factorcaution

One contributor made all commits in the last three months, so maintenance knowledge and release capacity are concentrated in a single person.

Repo commit activitycaution

Only one commit was recorded in the last three months, indicating limited recent development activity even though the package was released during that period.

Security policycaution

The repository has no security policy. That weakens the project's documented process for receiving and handling vulnerability reports.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Marko Cupic

Direct Dependencies

DependencyLast ReleaseScore
symfony/asset
Version ^6.4 || ^7.0
symfony/config
Version ^6.4 || ^7.0
contao/core-bundle
Version ^5.3
symfony/http-kernel
Version ^6.4 || ^7.0
league/oauth2-client
Version ^2.7

Weekly Downloads

Info

Last Published
1 month ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform