It has a clear MIT license, a complete README, repository tests, release notes, and a modest dependency footprint. The single-person project, absent security policy, and unpinned CI references add little reassurance.
56%
Total Score
50
100
83
50
The package has had no release in nearly two years: its latest release was December 11, 2024, despite being about 714 days old. This is a substantial maintenance concern for a Laravel integration package.
The repository is owned by an individual rather than an organization, so the single registry maintainer represents a limited visible backing structure. This matters more alongside the prolonged inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, supporting the evidence of a prolonged maintenance pause.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap for a package handling passwordless login links.
All 11 analyzed action references are unpinned, which weakens build reproducibility and update control. The audit found no dangerous triggers, untrusted checkouts, script injection, or high-confidence security findings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.