The package is small and clearly scoped, with a matching repository, MIT license, and only one runtime dependency. Its minimal documentation and lack of security tooling add little assurance for a dependency that has not changed since 2017.
42%
Total Score
25
100
71
83
The package has had only two releases, both in June 2017, with no releases in more than 9 years. This is strong evidence of abandonment risk for a dependency that may need compatibility updates.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with its last push in 2017. The long-standing absence of activity materially lowers maintenance confidence.
A single registry maintainer is reasonable for a small package, but it leaves little demonstrated maintenance capacity when combined with the absence of recent commits and releases.
The 48-character README is present, but the package and repository have no tests or changelog. Missing tests and changelog are normal packaging practice, while the very limited consumer documentation is a minor transparency gap.
The repository has 0 stars and 0 forks, providing no meaningful adoption evidence to offset the lack of recent maintenance. Popularity is only supporting evidence, but here it reinforces the uncertainty.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/oauth2-client Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.