The MIT license, focused five-file package, and clear README make the code easy to inspect and adopt. There are no tests or security tooling, and the tiny repository has little activity beyond its sole 2016 release.
42%
Total Score
50
100
72
88
The package has only one release, published about 10 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a dependency tied to an external OAuth provider.
The repository owner is an individual account rather than an organization, and no organizational backing is shown. That leaves a thin ownership base, although registry maintainer records alone are not used to infer activity.
There are no open issues or pull requests and no activity in the last month. This is consistent with a small, dormant project and offers no evidence of ongoing maintenance.
The repository has only 2 stars, 0 forks, and 1 watcher. Low popularity is supporting evidence rather than decisive on its own, but it provides little community support for an otherwise dormant package.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools are present. The missing scanning is a hygiene weakness, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version 5.2.* | — | — |
laravel/socialite Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.