The organization-backed repository includes tests, a matching license, and no install-time scripts. Its security policy and scanning coverage are absent, while the package has no established release or maintenance history yet.
68%
Total Score
75
100
88
83
This package is brand new: it has one release and no established release cadence. That limits evidence of long-term maintenance, although the zero-day age means it is not evidence of abandonment.
There were no commits or active maintainers in the prior three months, but the repository and package are only zero days old; this is limited history rather than demonstrated abandonment.
Composer is used as the build tool, but no security-scanning tools are reported. For a package handling type definitions, this is a modest transparency gap rather than a severe risk.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. The small package scope and presence of tests partly limit the concern, but do not replace a policy.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/oauth2-server Version 9.4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.