The repository includes a changelog, clear MIT licensing, and active recent development. It has no tests or security policy, and the project currently depends on one maintainer, so longer-term reliability remains unproven.
62%
Total Score
67
50
81
67
Six runtime dependencies, including Laravel components, Livewire, and an SMS provider library, create a meaningful compatibility surface but are consistent with the package's OTP and SMS functionality.
The package runs a post-autoload-dump install-time script. This is not necessarily unsafe, but it adds execution behavior that should be understood before adoption.
A changelog exists in both the package and repository, but there are no tests and no README in the published artifact. The missing tests reduce confidence for a Laravel integration package.
The repository is owned by an individual account rather than an organization, so the single-maintainer concentration is not offset by visible organizational backing.
The package is brand new: its first release was today and it has only two releases, so there is no established maintenance or compatibility history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ipe/smsir-php Version ^1.0 | — | — |
livewire/livewire Version ^4.0 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.