The package includes an MIT license, a README, tests, and release notes for this version. Its published release history and source activity are years old, while the registry and repository both indicate it is no longer maintained.
12%
Total Score
25
42
100
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency on it.
The latest release was in April 2016, with only four releases overall and none in the last 12 months. This strongly indicates abandonment for a web application package.
The repository had zero commits and zero active maintainers in the last three months, providing no evidence of ongoing maintenance.
The linked repository is archived, despite a last push in March 2022, so it is no longer an actively maintained source for this package.
There were no new or closed issues or pull requests in the last month, while ten pull requests remain open. This is consistent with an inactive project.
| Title | Versions | Severity |
|---|---|---|
CVE-2017-7390 movingbytes/social-network is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.2.1. | 0.0.0 - 1.2.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
textalk/websocket Version ^1.2 | — | — |
phpmailer/phpmailer Version ^5.2 | — | — |
league/oauth2-client Version ^1.3 | — | — |
league/oauth2-google Version ^1.0 | — | — |
altorouter/altorouter Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.