The README, tests, MIT license, small dependency set, and organization-backed repository provide a solid foundation. Maintenance has been quiet since the initial release burst, with no recent commits and limited security hygiene; the workflow also uses unpinned actions.
63%
Total Score
75
100
83
83
All three releases were published in an initial burst on one day, and there have been no later releases during the package's roughly seven-month lifetime. That leaves uncertainty about continued maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the stalled release history, this is a meaningful maintenance concern.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of any adoption signal provides no additional confidence for a young package.
Composer is used for the build, but no security scanning tools are configured. This is a hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/oauth2-client Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.