A lightweight and powerful OAuth 2.0 authorization and resource server library with support for all the core specification grants. This library will allow you to secure your API with OAuth and allow your applications users to approve apps that want to access their data from your API.
40%
Total Score
unhealthy
Risky: maintenance stopped in 2018 and the repository has no recent contributor activity.
The package has 74 releases but none in the last 12 months, and its latest release was in August 2018. That long period without a release is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the last 3 months. Combined with the old last push, this indicates a serious lack of ongoing maintenance capacity.
Seven runtime dependencies, including cryptography and token libraries, create meaningful maintenance surface, but the profile is not unusually broad for an OAuth server library.
The repository is owned by an individual rather than an organization, so the small maintainer base and inactive repository leave limited visible backing for continued maintenance.
The repository has zero stars and forks and only one watcher. Popularity is not required for health, but these values provide little supporting evidence of an active user or contributor community.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^3.2.2 | — | — |
league/event Version ^2.1 | — | — |
psr/http-message Version ^1.0.1 | — | — |
defuse/php-encryption Version ^2.1 | — | — |
paragonie/random_compat Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.