The package has clear usage instructions, a stable release, and an active organization-owned repository. Registry releases stopped about three years ago, while recent repository activity is absent and no security policy is provided.
55%
Total Score
67
100
83
83
There were zero commits and zero active maintainers in the last three months, indicating no recent development activity and increasing abandonment risk for a package whose registry releases are already stale.
The package borrows identity from the much more downloaded socialiteproviders/manager package, but artifact overlap is only 0.33 and the README identifies this as a FranceConnect provider rather than a copy. This is a naming concern, not evidence that consumers most likely wanted the lookalike.
The package has only four releases and has had no registry release in about three years, which materially weakens confidence in ongoing maintenance despite its multi-year history.
Composer is used for the build, which fits the package ecosystem, but no security-scanning tools are detected. This is a modest transparency and maintenance gap rather than a standalone severe risk.
The repository has no security policy, leaving vulnerability reporting expectations unspecified. For an OAuth provider, that is a meaningful but not disqualifying transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
socialiteproviders/manager Version ~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.