The package is a minimal five-file library with Composer build tooling and a README. Its stable release and matching repository do not offset roughly 10 years without activity or the missing license. The closed-source runtime dependency also limits transparency.
30%
Total Score
0
50
75
83
The latest release was in January 2016, with no releases in the last 12 months; roughly 10 years without a release indicates substantial abandonment risk.
The repository has had zero commits and zero active maintainers in the last three months, consistent with the long release gap and providing no evidence of current maintenance.
The package has two runtime dependencies, including a closed-source dependency, which reduces transparency for a library intended to support an OAuth flow.
No declared license, license file, or repository license file was detected, leaving the legal terms for using this dependency unclear.
The repository name matches the package name, supporting that it is the intended source; the README does not mention the package name, a minor documentation gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
timenomad/oauth2-php-closed-source Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.