The package is clearly identified, MIT-licensed, and has a simple published structure. Its only release was over 12 years ago, with no recent commits or active maintainers, making future compatibility and support unlikely.
35%
Total Score
38
50
67
67
There has been only one release, published over 12 years ago, with no releases in the last 12 months. This is strong evidence of abandonment and outdated compatibility.
There were zero commits and zero active maintainers during the last three months. Combined with the repository's age, this strongly supports an abandonment concern.
The package has four runtime dependencies, including its framework integration and Twitter authentication library. The count is not excessive, though the old dependency context increases compatibility uncertainty.
One registry maintainer is responsible for publishing the package, leaving little visible publishing redundancy. This is more concerning alongside the absence of recent project activity.
The registry namespace and repository owner match, and the owner is an individual user rather than an organization. This is consistent ownership but offers limited backing capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
opauth/twitter Version * | — | — |
composer/installers Version 1.* | — | — |
misfrog/cakephp-social Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.