Usable with caveats: the package is clearly licensed, tested, documented, and not deprecated or archived, but maintenance appears to have stopped after December 2025. Its broad dependency set and limited repository security hygiene add operational risk for a Symfony OAuth2 integration.
58%
Total Score
25
50
75
80
The repository recorded zero commits and zero active maintainers in the last 3 months. Combined with the last push being in December 2025, this is a meaningful maintenance and abandonment concern.
The package declares 31 runtime dependencies, including database, administration, security, and multiple framework integration bundles; this broad dependency surface increases upgrade and compatibility burden.
The registry namespace and repository owner match, and the repository is user-owned rather than organization-owned. This is consistent ownership evidence, but it provides less institutional backing than an organization-maintained project.
Five releases were published, including four in the last 12 months, with a median interval of about 3 days; this shows an initially active release process, although the latest release is now several months old.
Composer is used for builds, but no security-scanning tools were detected. This is a hygiene gap for an OAuth2-related package, though the repository does have CI workflows and tests.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3|^2|^1 | — | — |
doctrine/orm Version ^3.0 | — | — |
symfony/yaml Version ^7.3 | — | — |
doctrine/dbal Version ^4.0 | — | — |
symfony/config Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.