The package is licensed, documented, and published under an organization-backed project with a direct repository match. Its small release history and limited repository activity leave little evidence of durable maintenance.
42%
Total Score
83
100
78
88
The package explicitly borrows the identity of the much more established socialiteproviders/manager, which has far more downloads and releases. Even with no artifact overlap, consumers may have intended to select the lookalike package instead.
Only two releases exist, over roughly 33 days between them, so the project has limited release history from which to judge long-term stability. Its recent origin partly explains the small history.
The repository recorded zero commits and zero active maintainers in the last three months. The package is relatively young, but this still provides weak evidence of ongoing maintenance.
Composer is used as the build tool, but no repository security-scanning tool was detected. The missing scanning is a hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy. For a small OAuth provider this reduces the transparency of vulnerability reporting, though it does not establish abandonment or a defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
socialiteproviders/manager Version ^4.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.