The repository contains tests and the package has a clear MIT license, but it lacks a security policy. Its organization backing and matching repository help, yet the age and inactivity make this a poor default for a new dependency.
44%
Total Score
50
75
50
The latest release was published about five years ago, with no releases in the last 12 months. The historical 48-release record shows prior activity but does not offset the prolonged current gap.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the risk that maintenance has stopped.
There were no new or closed issues or pull requests in the last month, and no pull requests were merged. This supports the broader picture of an inactive project, although open issue data is unavailable.
Composer build tooling is present, but no security scanning tools were detected. This weakens ongoing assurance for a package handling authentication.
The linked repository has no published security policy. For an authentication module, that is a meaningful transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yawik/core Version ^1.0 | — | — |
hybridauth/hybridauth Version ^2.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.