The package includes a clear README, an MIT declaration, and release notes for PHP 8. Its linked organization-owned repository matches the package, but the registry release history and current commit activity provide limited evidence of ongoing maintenance.
52%
Total Score
83
100
85
83
The detector reports identity borrowing toward socialiteproviders/manager, but artifact overlap is zero and the matching repository identifies this as a distinct Pipedrive provider; the signal warrants caution without establishing a copy.
The package has had no registry release in nearly six years, despite four releases overall; this materially raises maintenance and abandonment risk.
No commits or active maintainers were recorded in the last three months, which weakens the evidence of active maintenance even though the repository is not archived.
Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency and hygiene gap rather than a severe risk.
The repository has no security policy, reducing guidance for reporting vulnerabilities in an OAuth provider, though this alone does not make the release unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
socialiteproviders/manager Version ~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.