Usable with caveats: it is licensed, documented, tested, and not deprecated or archived, but maintenance appears stalled, with no registry release in about three years and no recent repository activity. Adopt it only if its dependencies and breaking-change history fit your project.
58%
Total Score
33
100
81
67
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the multi-year release gap, this is the main abandonment risk.
The package and repository are owned by the same individual account, so the project has clear ownership but no visible organizational backing to compensate for a single-maintainer structure.
The package has nine releases over roughly ten years, but it has had no release in about three years. That long gap raises maintenance and compatibility concerns for a security-sensitive client library.
There are nine open issues and six open pull requests, with no new or closed issues and no merged pull requests in the last month. The unresolved queue provides some evidence of unattended maintenance.
Composer build tooling is present, but no security-scanning tool was detected. For an OAuth2/OpenID Connect client, that is a meaningful hygiene gap, though the absence alone does not make the package unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ~4.0 | — | — |
webmozart/assert Version ^1.10 | — | — |
league/oauth2-client Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.