Risky to adopt: the package has had no registry release since December 2020 and shows no recent commit activity. Its repository is active and organization-backed, but the strong resemblance to the much more established socialiteproviders/manager package makes the package identity a serious concern.
42%
Total Score
75
100
75
83
The package explicitly borrows the identity of socialiteproviders/manager, which has about 2.85 million monthly downloads and 76 stable releases versus 7,855 downloads and 3 releases here. Although the artifact overlap is zero, the identity borrowing is strong evidence that consumers may have intended to select the established package instead.
The package has only 3 releases over roughly 9.5 years and no releases in the last 12 months; its latest registry release was in December 2020. This is a substantial maintenance and compatibility concern despite the package's stable version status.
The linked repository recorded 0 commits and 0 active maintainers in the last 3 months, providing no evidence of ongoing development to offset the stale registry release history.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, but it is secondary to the package's stale release history and identity concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
socialiteproviders/manager Version ~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.