Package Health

zrobot/flarum-gitea-org-oauth

The package is small and clearly documented, with a focused dependency set and no install-time scripts. Its source has had no commits or active maintainers in the past three months, and it has no security scanning; pin v0.1.5 and reassess maintenance before upgrading.

Latest v0.1.5PackagistPackagist

56%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo commit activitydanger

The repository had zero commits and zero active maintainers in the past 3 months, while its last push was about 8 months ago. That is direct evidence of currently inactive maintenance for a young package.

Release historycaution

All six releases arrived within about 7 hours on the same day, so the package has limited evidence of an established release process despite being available for about 8 months.

Repo popularitycaution

The repository has zero stars, forks, and watchers. This is weak supporting evidence rather than a verdict, but it provides no external adoption signal to offset the lack of recent activity.

Repo toolingcaution

Composer is used as the build tool, but no security scanning tools are configured. The missing scanning reduces maintenance and supply-chain transparency.

Security policycaution

The repository has no security policy, leaving no documented route for reporting vulnerabilities or communicating security fixes.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
fof/oauth
Version ^1.7
—
—
flarum/core
Version ^1.8
—
—
league/oauth2-client
Version ^2.7
—
—

Weekly Downloads

Info

Last Published
8 months ago
Created
8 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform