The repository still supplies tests, a changelog, licensing, and a security policy. Its workflows have weak pinning and low-confidence cache warnings, so pinning this old release deserves extra care.
55%
Total Score
50
100
81
100
The package and repository are owned by the same individual account rather than an organization, so the small maintainer and inactive-activity signals are not offset by visible organizational backing.
The package has 59 releases since 2014, but none in the last three years, indicating a substantial maintenance gap despite its long history.
There were no commits and no active maintainers in the last three months, which is a concrete sign of currently stalled maintenance.
The repository has zero stars, forks, and watchers, offering no adoption evidence and suggesting a very small project footprint, though popularity alone is not decisive.
The registry's latest version is 2.1.0 while this assessment covers the older 1.0.0-rc.5.1 release, reducing confidence that this specific release remains current.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
namshi/jose Version ^7.0 | — | — |
lcobucci/jwt Version ^3.2 | — | — |
nesbot/carbon Version ^1.0|^2.0 | — | — |
illuminate/auth Version ^5.1|^6 | — | — |
illuminate/http Version ^5.1|^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.