The source includes tests, documentation, and matching package references, while the MIT license is clear. Its maintenance appears abandoned, with no commits or releases since 2017 and no security scanning or policy.
35%
Total Score
50
67
50
The package has had only one release, first published in September 2017, with no releases in the last 12 months. This strongly raises abandonment risk for a library dependency.
There were zero commits and zero active maintainers in the last three months. Combined with the old release history, this indicates maintenance has effectively stopped.
Composer build tooling is present, but no security scanning tools are configured. For an authentication library, this is a meaningful transparency and maintenance gap.
The repository is not archived, which is a positive counterpoint, but its last push was in October 2017 and does not offset the long period without maintenance.
The repository has no security policy. That leaves vulnerability reporting and maintainer response expectations undocumented for an authentication package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
namshi/jose Version ^7.0 | — | — |
nesbot/carbon Version ^1.0 | — | — |
illuminate/auth Version 5.1.* || 5.2.* || 5.3.* || 5.4.* || 5.5.* | — | — |
illuminate/http Version 5.1.* || 5.2.* || 5.3.* || 5.4.* || 5.5.* | — | — |
illuminate/support Version 5.1.* || 5.2.* || 5.3.* || 5.4.* || 5.5.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.