The package is tiny and easy to inspect, with a focused dependency set and clear usage documentation. No security policy or scanning is present, making vulnerability response difficult to verify.
38%
Total Score
25
100
79
75
The package has only two releases, with the latest published in October 2014 and none in the last 12 months. This long period without releases is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package having received no maintenance for many years.
Only one registry maintainer is listed, and the repository is user-owned rather than organization-backed. This leaves limited visible publishing continuity, though the small project scope partly reduces the concern.
Composer is used for builds, but no security scanning tool is configured. That leaves dependency and source vulnerabilities without an automated detection signal.
The repository has no security policy, so there is no documented vulnerability-reporting or response process for consumers to rely on.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
opauth/opauth Version >=0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.