The project is very young and all six recent commits came from one contributor. It has organization backing, a declared license, a readme, and no registry deprecation, but no tests, security policy, or scanning evidence.
65%
Total Score
67
100
88
75
The package is only 66 days old with three releases concentrated over about one day, so its maintenance record is still too short to establish maturity.
One contributor made 100% of the recent commits. Organization backing partly offsets handoff risk, but the observed contributor base remains concentrated.
Six commits were made in the last three months, but activity came from only one active maintainer, limiting evidence of durable maintenance capacity.
Composer build tooling is present, but no security scanning tools are configured, leaving a meaningful security-maintenance gap for an OAuth server.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in a security-sensitive package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
skeeks/cms Version ^6.4 || dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.