This is a newly published, stable MIT-licensed package with a small and understandable dependency profile, no deprecation status, no install-time lifecycle scripts, and a non-archived repository. However, it has only one release and one commit, all recent activity is from a single contributor, the repository does not clearly identify or mention the package, and the repository lacks tests, a changelog, security scanning, and a security policy. The release workflow also has top-level write permissions. It may be usable, but its very limited history and transparency make it a cautious dependency choice until the project demonstrates sustained maintenance and clearer repository/package linkage.
58%
Total Score
63
100
72
75
A README is present, and the absence of tests and a changelog is not independently severe for this small package, but the repository also has no tests or changelog, reducing maintenance transparency.
The repository is owned by an individual user rather than an organization, so there is no organizational backing to offset the concentrated maintainer and contributor base.
This package is only 0 days old with one release and no established release cadence, so there is little evidence of maturity or sustained maintenance.
All one recent commit came from a single contributor, leaving maintenance highly concentrated and vulnerable to abandonment.
Only one commit was recorded in the last 3 months, so the project has not yet demonstrated sustained implementation or maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/oauth2-client Version ^2.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.