It has a clear Apache-2.0 license, tests, and a structured source tree. Its small dependency surface and organization ownership provide useful context, but not ongoing support.
12%
Total Score
50
50
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on it.
The latest release was in November 2020, with no releases in the last 12 months and only five releases overall. The nearly six-year gap indicates the package is no longer actively maintained.
The repository recorded zero commits and zero active maintainers in the last three months. This corroborates the abandonment signals rather than showing merely a slow release cadence.
The linked repository is archived, and its last push was about four years ago. An archived source project is a severe abandonment risk for a dependency.
The repository uses Composer, showing a defined build tool, but it reports no security scanning tools. This is a modest hygiene gap in an otherwise abandoned project.
| Title | Versions | Severity |
|---|---|---|
CVE-2013-4701 openid/php-openid is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 2.3.0. | 0.0.0 - 2.3.0 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.