The repository has minimal project safeguards, and commit activity has stopped in the last three months. The MIT declaration, README, and organization backing provide useful transparency, but the release appears difficult to trust as a dependency.
38%
Total Score
83
100
72
83
The signal identifies this package as borrowing the identity of the much more established socialiteproviders/manager, with 222 monthly downloads versus 2,849,777 and borrows_lookalike_identity set to true. Consumers may have intended the lookalike package, making this a severe dependency-selection risk despite the repository matching this package.
The package has four releases over roughly nine years, with no release in the last five years since June 2021. That is strong evidence of a stale registry release, although the linked repository has been pushed recently.
No commits and no active maintainers were recorded in the last three months. The recent repository push limits the abandonment conclusion, but the absence of observed recent commit activity remains a maintenance caution.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a standalone severe risk.
The repository has no security policy, leaving vulnerability reporting and response expectations unspecified.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
socialiteproviders/manager Version ~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.