The project has an MIT license, a clear README, and regular early releases. Its organization-backed repository is not archived, but no commits or issue activity were recorded in the last three months and it has no security policy or scanning.
64%
Total Score
67
100
89
75
No commits and no active maintainers were recorded during the last three months. This is a meaningful maintenance concern, although the recent release history provides some compensating evidence.
There were no new or closed issues or pull requests in the last month. With no open issues or pull requests, this is limited evidence of inactivity rather than a severe abandonment signal.
The repository has zero stars, forks, and watchers, indicating little visible adoption or community support. Popularity is supporting evidence only, so this lowers confidence more than it determines the verdict.
Composer build tooling is present, but no security scanning tools were detected. For an OAuth API integration, the missing security automation is a modest transparency and maintenance gap.
No security policy was found in the linked repository, leaving vulnerability-reporting expectations unclear for a package that handles API credentials.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
league/oauth2-client Version ^2.7 | — | — |
select-co/module-core Version ^1.0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.