Package Health

phinocio/oauth2-nexus-mods

This is a newly published, stable MIT-licensed package with a small and understandable dependency profile, no deprecation status, no install-time lifecycle scripts, and a non-archived repository. However, it has only one release and one commit, all recent activity is from a single contributor, the repository does not clearly identify or mention the package, and the repository lacks tests, a changelog, security scanning, and a security policy. The release workflow also has top-level write permissions. It may be usable, but its very limited history and transparency make it a cautious dependency choice until the project demonstrates sustained maintenance and clearer repository/package linkage.

Latest 1.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health checks

Package scaffoldingcaution

A README is present, and the absence of tests and a changelog is not independently severe for this small package, but the repository also has no tests or changelog, reducing maintenance transparency.

Project backingcaution

The repository is owned by an individual user rather than an organization, so there is no organizational backing to offset the concentrated maintainer and contributor base.

Release historycaution

This package is only 0 days old with one release and no established release cadence, so there is little evidence of maturity or sustained maintenance.

Repo bus factorcaution

All one recent commit came from a single contributor, leaving maintenance highly concentrated and vulnerable to abandonment.

Repo commit activitycaution

Only one commit was recorded in the last 3 months, so the project has not yet demonstrated sustained implementation or maintenance activity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Phinocio

Direct Dependencies

DependencyLast ReleaseScore
league/oauth2-client
Version ^2.9

Weekly Downloads

Info

Last Published
15 days ago
Created
15 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform