The package is small, clearly documented, uses an MIT declaration, and has no install-time scripts. Its single-user ownership and lack of security tooling provide limited independent assurance.
55%
Total Score
50
100
86
83
Only one registry publisher is listed, leaving little visible publishing redundancy; the linked project is also user-owned rather than organization-backed.
The repository owner is a user account matching the registry namespace, so ownership is coherent, but there is no organization backing shown to compensate for the thin maintainer base.
All five releases appeared within roughly one day, followed by about 101 days without a newer release; this suggests an unproven maintenance cadence for a young package.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the registry's long pause and weakening confidence in ongoing maintenance.
Composer build tooling is present, but no security scanning tools were detected, leaving a meaningful assurance gap for an authentication integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/socialite Version ^5.27 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
socialiteproviders/keycloak Version ^5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.