Risky to adopt: the package has had no release or repository activity since 2016, making abandonment a serious concern. It has useful documentation, tests, and a license, but those strengths do not offset its age and inactive maintenance.
42%
Total Score
0
100
67
75
The package has only two releases, both from February 2015, with no releases in the last 12 months and a latest release more than 11 years old. This is strong evidence of an unmaintained dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap and indicating no current maintenance capacity.
Composer build tooling is present, but no security scanning tooling is configured. The lack of scanning is a transparency gap, though the much older maintenance gap is the more consequential concern.
The repository is not archived, which preserves a path for future maintenance, but its last push was in April 2016 and the repository has otherwise shown no recent activity.
The repository has no security policy. For a library handling an OAuth API, this reduces transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.