Healthy and actively maintained, with clear documentation, regular releases, and organizational backing. The main caveats are that all recent commits come from one contributor and the repository has no security-scanning tooling or tests.
78%
Total Score
83
100
88
100
The package includes a substantial README and changelog, and the repository uses GitHub Releases. Tests are absent, which is a maintenance-quality gap for a plugin handling authentication flows.
One contributor made all 12 commits in the last 3 months, creating a genuine continuity risk. Organizational ownership partly offsets this, but no second active contributor is shown.
Composer is used for builds, but no security-scanning tools are configured. This is a transparency and assurance gap, though it is not evidence of abandonment.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10877 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. verbb/social-login is vulnerable to Improper Authentication in versions 1.0.0 - 1.0.23 and 2.0.0 - 2.0.11. | 1.0.0 - 1.0.232.0.0 - 2.0.11 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
verbb/auth Version ^2.0.40 | — | — |
verbb/base Version ^3.0.4 | — | — |
craftcms/cms Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.