It has a clear README, tests, and a small runtime dependency set. The licensing conflict and extended lack of maintenance make this release a poor default choice.
48%
Total Score
50
71
75
The manifest declares MIT, but the bundled LICENSE.md is identified as AGPL-3.0. Although a license file exists, the mismatch creates a material legal and adoption risk until clarified.
The latest release was published in January 2022, with no releases in the following 12 months covered by the signal. This indicates the package has not been refreshed for several years.
The repository recorded 0 commits and 0 active maintainers over the last 3 months, consistent with the long release gap and raising abandonment concerns.
The project uses Make and Composer, but no security-scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe release by itself.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This matters for middleware involved in access-token verification.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.0|^7.0 | — | — |
illuminate/support Version ^6.0|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.