Documentation, tests, and a small dependency surface make integration straightforward. The project lacks a security policy and has limited community adoption, so future support may be constrained.
59%
Total Score
50
100
83
88
Registry publishing access is held by one maintainer. This is consistent with the individually owned repository, but it leaves limited visible publishing redundancy if that maintainer becomes unavailable.
The package has only two releases, with no release in more than four years and a long median interval between releases. This is the strongest evidence of reduced maintenance activity.
There were no commits and no active maintainers in the measured three-month period, consistent with the repository's last push being in December 2021. This indicates substantial maintenance inactivity.
The repository has three stars, no forks, and one watcher, indicating limited community adoption. Popularity is supporting evidence only, so this modestly reinforces the support-capacity concern rather than determining the verdict.
Composer is used as the build tool, but no security scanning tools were detected. The missing scanning is a modest hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/oauth2-client Version ^2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.