Package Health

socialiteproviders/xero

The repository is correctly linked, backed by an organization, and the release is stable with clear usage documentation. A security policy and automated security scanning are also absent.

Latest 4.2.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Name lookalikedanger

The package is flagged as borrowing the identity of the much more established socialiteproviders/manager, with borrows_lookalike_identity true. Although artifact overlap is zero, consumers may have intended to install the lookalike package instead.

Release historycaution

The latest release was in September 2023, with no releases in the last 12 months. Its earlier five-release history shows the package was once active but does not offset the prolonged release gap.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance warning even though it was pushed more recently overall.

Security policycaution

The linked repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, but it is less severe than the maintenance and identity concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ryan Marshall

Direct Dependencies

DependencyLast ReleaseScore
firebase/php-jwt
Version ^6.8
—
—
socialiteproviders/manager
Version ^4.4
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform