The repository includes tests, a substantial README, release notes, and a matching source project. Ongoing maintenance and workflow hygiene remain limited, so pinning this release is safer than assuming continued support.
58%
Total Score
50
100
88
75
The package and repository are owned by the same individual account, providing clear ownership but no organizational backing or broader support structure.
This package is about five and a half months old but has published only one release, leaving little evidence of an established release track. The matching repository and release notes provide some transparency, but they do not offset the thin history.
No commits and no active maintainers were recorded in the last three months. For a package intended to track current Laravel releases, this is a meaningful maintenance concern despite the recent initial release.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/socialite Version ^5.18 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.