Healthy and suitable to adopt, with strong recent maintenance and solid repository hygiene. It is a young pre-1.0 package with only two active contributors and no security policy, so review upgrades carefully.
86%
Total Score
75
100
89
90
The registry namespace and repository owner match, but the owner is an individual rather than an organization. This is consistent ownership, though it provides less organizational maintenance redundancy.
Two contributors are active, with the leading contributor responsible for about 68% of recent commits. The second contributor accounts for about 32%, which reduces but does not eliminate single-maintainer risk.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this lowers external validation somewhat but does not outweigh the demonstrated release and commit activity.
No repository security policy was found. For an authentication package, this is a genuine transparency and vulnerability-reporting gap, although active development and security scanning provide partial compensation.
Version v0.16.0 is not a stable major release, so its API and behavior may still change. It is not marked as a prerelease, which provides some compensation but does not remove the pre-1.0 compatibility risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version ^7.4 || ^8.0 | — | — |
lcobucci/jwt Version ^5.6 | — | — |
illuminate/auth Version ^13.0 | — | — |
illuminate/http Version ^13.0 | — | — |
illuminate/mail Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.