Healthy, but still an early 0.x release that should be pinned and tested before adoption. It has exceptionally active recent development, three active contributors, tests, substantial documentation, and a matching organization-backed repository; security-policy and workflow-permission gaps are the main caveats.
78%
Total Score
100
100
81
80
The package is only 92 days old but has 35 releases, including 34 in the last 12 months and a median interval of about 9 hours. This shows active iteration, though the very rapid cadence warrants pinning and testing.
Composer build tooling is present, but no security-scanning tool was detected. That is a transparency and assurance gap for a package handling credentials, though it is not evidence of abandonment.
The repository has no security policy. For a package whose README describes credential and authentication functionality, the missing reporting guidance is a genuine transparency gap.
The only workflow lacks a top-level permissions declaration. No write permissions were detected, but explicitly constraining token access would provide stronger workflow hygiene.
Version v0.15.0 is not a stable major release, and the README explicitly describes the 0.x release as still being finalized. It is usable, but compatibility may change before 1.0.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
composer/semver Version ^3.4 | — | — |
illuminate/auth Version ^13.24 | — | — |
paragonie/paseto Version ^3.5 | — | — |
illuminate/console Version ^13.24 | — | — |
illuminate/process Version ^13.24 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.