Package Health

steverhoades/oauth2-openid-connect-client

Usable with caveats: it is licensed, documented, tested, and not deprecated or archived, but maintenance appears stalled, with no registry release in about three years and no recent repository activity. Adopt it only if its dependencies and breaking-change history fit your project.

Latest v2.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers during the last three months. Combined with the multi-year release gap, this is the main abandonment risk.

Project backingcaution

The package and repository are owned by the same individual account, so the project has clear ownership but no visible organizational backing to compensate for a single-maintainer structure.

Release historycaution

The package has nine releases over roughly ten years, but it has had no release in about three years. That long gap raises maintenance and compatibility concerns for a security-sensitive client library.

Repo issue activitycaution

There are nine open issues and six open pull requests, with no new or closed issues and no merged pull requests in the last month. The unresolved queue provides some evidence of unattended maintenance.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. For an OAuth2/OpenID Connect client, that is a meaningful hygiene gap, though the absence alone does not make the package unfit.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Steve Rhoades

Direct Dependencies

DependencyLast ReleaseScore
lcobucci/jwt
Version ~4.0
—
—
webmozart/assert
Version ^1.10
—
—
league/oauth2-client
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform