Its Apache-2.0 license, clear README, and minimal metapackage design make its purpose and consumption straightforward. The linked organization repository is clean but has not yet demonstrated ongoing activity.
64%
Total Score
75
100
86
88
The package was first released today and has only one release, so there is no demonstrated release continuity yet. This is a meaningful maturity gap, though the package is intentionally versioned alongside the upstream API.
There were no commits and no active maintainers in the last three months, but the repository and package were created today. This limits evidence of ongoing maintenance rather than proving abandonment.
The repository uses Composer, appropriate for this package, but has no reported security-scanning tooling. For a tiny metapackage this is a hygiene gap rather than a severe risk.
The repository has no security policy. That reduces disclosure transparency, although the package is a minimal type-definition wrapper with no reported runtime code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/league-oauth2-server-impl Version ~9.4.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.