The MIT license, matching source tree, release notes, and no install scripts improve transparency. The small user base, absent security policy, and lack of recent recorded commit activity leave limited evidence of sustained maintenance.
68%
Total Score
75
100
83
83
The package is 719 days old with 13 releases, but only one release in the last 12 months. That indicates a slowing cadence, though the assessed version was released at collection time.
No commits or active maintainers were recorded in the previous three months. The current release and same-day repository push provide some counter-evidence, but sustained maintenance is still not demonstrated.
The repository has one star and no forks, indicating very limited independent adoption evidence. Popularity is supporting evidence rather than a health verdict, so this is a modest concern.
Composer build tooling is present, but no security scanning tools were detected. This weakens repository hygiene evidence without showing that the package is unsafe.
The repository has no security policy. For an OAuth 2.0 API client, the absence reduces transparency around vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 || ^8.0 | — | — |
symfony/polyfill-php83 Version ^1.0 | — | — |
symfony/http-foundation Version ^5.0 || ^6.0 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.