Organization backing, a matching repository, and release notes provide some transparency. The package has no tests, security policy, or recent commit activity, leaving ongoing support uncertain.
40%
Total Score
75
100
78
83
The package explicitly borrows the identity of the much more established socialiteproviders/manager, with 2,885,443 monthly downloads versus 222 and no evidence it is a transparent fork or integration. This creates a serious risk that consumers may select it when they intended the lookalike package.
The package has only two releases, with the latest published on October 1, 2022, and none in the last 12 months. The long release gap materially raises abandonment risk, despite the package not being deprecated.
The repository recorded zero commits and zero active maintainers in the last three months. Although it was pushed recently and is not archived, the observed development activity does not show active maintenance.
The linked repository has no security policy. This is a transparency and maintenance gap for a package handling OAuth credentials, with no provided evidence compensating for it.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
socialiteproviders/manager Version ~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.