Clear documentation, licensing, and a long record of stable releases support adoption. Recent source activity is thin and concentrated, while the organization backing reduces—but does not remove—the maintenance risk.
78%
Total Score
67
94
83
One contributor made all commits in the last 3 months, concentrating recent source activity in a single person. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Only 1 commit was recorded in the last 3 months, indicating limited recent development activity despite the recent package release. This is a maintenance caution.
The repository uses Make and Composer, but no security-scanning tools were detected. For a package handling authentication and cloud integrations, that is a modest transparency and maintenance gap.
No security policy was found in the repository. This weakens the project's documented process for reporting and handling security issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
google/auth Version >=1.46.0 | — | — |
google/cloud Version >=0.277.0 <1.0.0 | — | — |
guzzlehttp/guzzle Version ^7.8.2 | — | — |
laravel/framework Version ~12 | — | — |
kelvinmo/simplejwt Version ^1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.