It has clear documentation, tests, a changelog, and a small runtime dependency surface. The source repository is not archived, but its lack of recent activity leaves compatibility and maintenance uncertain.
45%
Total Score
0
100
69
67
The latest registry release was over 7 years ago, with no releases in the last 12 months. That long release gap is a substantial maintenance and compatibility concern despite six historical releases.
There were no commits and no active maintainers in the last 3 months. Combined with the old last push, this indicates effectively dormant project maintenance.
Composer build tooling is present, but no security scanning tools were detected. For a dormant library this is a modest transparency and maintenance gap, not a severe risk by itself.
The repository is not archived, which avoids an abandonment verdict, but it was last pushed over 11 years ago. The non-archived status does not compensate for that inactivity.
The repository has no security policy. That leaves vulnerability reporting and response expectations undocumented, which matters for an OAuth client library.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.