Usable with caveats: it is a small, recently published package with an active, non-archived repository and organization backing. However, only two releases exist, all recent commits come from one contributor, and the project has no tests, changelog, or security policy.
68%
Total Score
75
100
81
90
The package includes a README and uses GitHub Releases, but has no tests or changelog in either the artifact or repository. For an OAuth package, the absence of tests is a meaningful maintenance and regression risk.
The package is only 36 days old with two releases and a median interval of about 36 days. This shows recent publishing activity but provides little long-term maintenance evidence.
One contributor made all two commits in the last three months, creating a concentrated maintenance dependency. Organization backing partly compensates because maintenance can potentially be handed off internally.
The repository recorded two commits in the last three months with one active maintainer. Recent activity is present, but the volume is too low to demonstrate sustained maintenance.
The repository uses Composer for builds, but no security scanning tools are configured. The missing scanning is a transparency gap, though the package has a small dependency profile.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.