The package is clearly identified, MIT-licensed, documented, and has a clean install profile. Its long period without releases or source changes makes future compatibility and support uncertain.
38%
Total Score
75
83
75
Only two releases were published, with the latest nearly seven years ago and none in the last 12 months. This is strong evidence of abandonment risk despite the short initial 21-day release interval.
The repository has had no commits and no active maintainers in over five years. The repository is not archived, but the absence of recent work still leaves compatibility and maintenance uncertain.
Composer is used for the build, which supports reproducible package management, but no security scanning tools are present. For a small plugin this is a hygiene gap rather than a standalone adoption blocker.
The repository has no security policy, reducing transparency about how vulnerabilities would be reported and handled. This adds to the maintenance concern but is less serious than the prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dukt/social Version ^2.0.0-beta.10 | — | — |
craftcms/cms Version ^3.0.0-RC1 | — | — |
omines/oauth2-gitlab Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.