The project has clear licensing, strong documentation, and a recent release with extensive security fixes. Automated checks are complete, though workflow actions are not pinned and security scanning is not reported.
82%
Total Score
83
100
94
75
Two contributors are active, but one made five of six recent commits, leaving maintenance substantially concentrated despite organization backing.
Composer build tooling is present, but no security scanning tools are reported for a package handling authentication and tokens; this is a modest transparency gap.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. Both action references are unpinned, which weakens reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^5.0 | — | — |
laravel/passport Version ^12.0|^13.0 | — | — |
defuse/php-encryption Version ^2.4 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.