Its single runtime dependency and lack of install scripts limit integration and installation concerns. Organization backing and a matching, non-archived repository provide some reassurance.
68%
Total Score
100
100
67
50
The package published 16 releases in 15 days, then had no recorded release for about eight months. That burst followed by a long pause weakens confidence in sustained maintenance.
Composer is used for builds, but no security-scanning tools are present. The build setup is established, while the absence of automated security checks modestly lowers assurance.
The repository has no security policy, leaving vulnerability-reporting expectations and handling procedures undocumented. This is a meaningful transparency gap, though it is not evidence of a security incident.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
microsoft/microsoft-graph Version ^2.32.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.