The source is a small, organization-backed provider with a matching repository, clear README, and documented release. Recent maintenance evidence is limited, while the naming concern creates a serious adoption risk.
42%
Total Score
75
100
81
75
The package is flagged as borrowing the identity of socialiteproviders/manager, which has 2,885,443 monthly downloads versus 1,720 for this package. Although artifact overlap is 0.0 and the repository clearly identifies Zendesk, the identity signal still creates a serious risk that consumers wanted the lookalike package.
The package has existed since February 2015 and has 14 releases, but it has had no release in the last 12 months; its latest release was December 4, 2024. That weakens confidence in ongoing maintenance for a dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months. A push occurred on February 21, 2026, but the recent activity window still shows limited demonstrated maintenance.
The linked repository has no security policy. This is a transparency and reporting gap, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
socialiteproviders/manager Version ^4.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.