The package has a clear README, focused dependencies, release notes, and a repository that matches its package name. Its source project is not archived, but recent commit activity is absent and no security policy is published.
42%
Total Score
75
100
72
83
The package is reported to borrow the identity of socialiteproviders/manager, which has far more downloads and stable releases; the rule treats this as strong evidence that consumers may have wanted the lookalike instead.
The latest registry release was 2020-12-01, with no releases in the last 12 months. The long gap materially raises abandonment and compatibility risk despite the package's earlier release history.
The repository recorded zero commits and zero active maintainers in the last three months. This weakens evidence of active maintenance, although the repository itself is not archived.
Composer build tooling is present, but no security-scanning tool was detected. For this small provider, that is a hygiene gap rather than a decisive adoption blocker.
The linked repository has no published security policy, reducing transparency for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
socialiteproviders/manager Version ~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.