The package includes a README, repository tests, and no install-time scripts. Its MIT license and small dependency set help, but they do not offset the long abandonment gap.
18%
Total Score
0
67
50
The published artifact contains files named id_rsa2 and id_rsa2.pub alongside the source. Even without evidence that the private-key-named file is usable, including it is a serious packaging hygiene concern for a dependency.
The package has had only two releases, both in April 2014, with no release in roughly 12 years. This is strong evidence of abandonment for an authentication library.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push occurring in October 2014. There is no observed recent maintenance to offset the age of the release.
The repository has zero stars and forks and only one watcher, providing little supporting evidence of community review or adoption. Popularity is secondary, but it does not compensate for the inactive project.
The repository is not archived, which avoids the strongest abandonment signal, but its last push was still in October 2014 and does not compensate for the lack of current activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hybridauth/hybridauth Version 3.0.0.*@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.