The package includes clear usage documentation, an MIT declaration, and a stable Composer dependency profile. Repository security policy and recent commit activity are absent, increasing maintenance and transparency concerns.
42%
Total Score
75
100
78
75
The package borrows the identity of socialiteproviders/manager, which has far more downloads and stable releases; the signal marks it as an identity copy rather than a transparent fork or integration.
Only one release exists, published about five years ago, with no releases in the last 12 months. The repository was pushed more recently, but that does not compensate for the stale registry release cadence.
There were no commits and no active maintainers in the last three months. The recent repository push is compensating evidence that the project is not abandoned outright, but current development activity remains weak.
Composer is used for the build, but no repository security scanning tools were detected. For a small provider this is a modest transparency gap rather than a severe risk.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
socialiteproviders/manager Version ~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.