The package has had no registry release in 763 days, and no commits in the last three months. Its matching organization repository, README, and GitHub release provide useful context, but do not remove the identity concern.
45%
Total Score
75
100
75
83
The package is flagged as borrowing the identity of socialiteproviders/manager, which has far more downloads and stable releases. Although artifact overlap is 0 and the README identifies the Atlassian provider, the identity signal remains a serious adoption risk.
This release is the package's only release, published 763 days ago, with no releases in the last 12 months. That leaves little evidence of an ongoing registry release cadence.
The repository recorded no commits and no active maintainers in the last three months. This weakens evidence of current maintenance, although the repository was pushed more recently than the package's last registry release.
The repository has 0 stars and 1 fork, indicating limited visible adoption. Popularity is supporting evidence only, so this modestly reinforces the maintenance concern rather than determining the verdict.
The repository has no security policy. For a small OAuth integration this is a transparency gap, though it is less significant than the maintenance and identity concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
socialiteproviders/manager Version ^4.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.