The repository has no security policy or automated security scanning, although the package is small and its files match the source repository. Its README and release notes provide useful integration guidance.
42%
Total Score
75
100
71
83
The package borrows the identity of the much more established socialiteproviders/manager, with 2,884,443 monthly downloads versus 246 and borrows_lookalike_identity=true. Although artifact overlap is zero, consumers may have intended to select socialiteproviders/manager instead.
The latest registry release was published more than five years ago, with no releases in the last 12 months and only three releases overall. The repository was pushed more recently, but that does not demonstrate a current release cadence.
There were no commits and no active maintainers in the last three months, reinforcing the concern that release maintenance has slowed despite the repository not being archived.
Composer build tooling is present, but no security scanning tools were detected. The build setup supports reproducibility, while the missing scanning reduces assurance.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though it is less severe for this small OAuth provider than for security-sensitive infrastructure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
socialiteproviders/manager Version ~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.