Usable with caveats: the package has a real organization-backed repository, tests, a license, and no install-time scripts, but maintenance appears stalled and the release remains on an unstable 0.x line. Review whether the lack of recent development and security documentation fits your risk tolerance.
62%
Total Score
75
79
75
The package has 11 releases over about 2 years, but none in the last 12 months; this indicates that maintenance and compatibility updates may have stalled.
There were zero commits and zero active maintainers in the last 3 months, a material sign of currently inactive maintenance when combined with no registry releases in the last year.
The repository uses Make and Composer build tooling, but no security scanning tools were detected, leaving a security-maintenance gap.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in an OAuth server bundle.
The single workflow has no top-level token permissions declaration. Although no write permissions or dangerous workflow patterns were observed, explicit least-privilege settings would provide stronger CI hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.0 || ^3.0 | — | — |
symfony/config Version ^5.4|^6.0|^7.0 | — | — |
symfony/http-kernel Version ^5.4|^6.0|^7.0 | — | — |
symfony/http-foundation Version ^5.4|^6.0|^7.0 | — | — |
symfony/security-bundle Version ^5.4|^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.