It includes tests, a usable README, and no install-time scripts. The single maintainer, absent security policy, unpinned workflow actions, and MIT/Apache-2.0 mismatch add adoption risk.
43%
Total Score
50
64
50
The package has had no release in more than three years, despite seven releases overall; this strongly raises abandonment risk for a security-sensitive integration library.
There were no commits and no active maintainers in the last three months, consistent with the multi-year release gap and indicating a substantial abandonment risk.
The manifest declares MIT, while the artifact license file is detected as Apache-2.0. A license file exists, but the mismatch creates legal and provenance ambiguity.
There were no new or closed issues or pull requests in the last month, and no open work is visible. This provides no evidence of ongoing community maintenance.
The project uses Composer, but no security scanning tools were detected. For an identity and SAML library, that is a meaningful repository hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/auth Version ^6.0|^7.0|^8.0|^9.0 | — | — |
illuminate/http Version ^6.0|^7.0|^8.0|^9.0 | — | — |
symfony/workflow Version ^6.0 | — | — |
illuminate/console Version ^6.0|^7.0|^8.0|^9.0 | — | — |
illuminate/hashing Version ^6.0|^7.0|^8.0|^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.