The package has clear licensing, tests, and consumer documentation. Its lone maintainer, absent security policy, and weak workflow hygiene leave little support for future fixes.
8%
Total Score
25
50
38
50
Packagist marks the entire package as abandoned and names claudiodekker/laravel-auth-core as its replacement. This directly makes the assessed package unfit as a new dependency.
This package has only one release, published about 3 years and 10 months ago, with no releases in the last 12 months. That strongly indicates the release line is inactive.
The repository recorded zero commits and zero active maintainers in the last 3 months. Together with the old last push and archive status, this supports an abandonment concern.
The linked repository name does not match the package name and its README does not mention the package. This raises concern that the repository may not actually correspond to the published release.
The linked repository is archived and was last pushed about 3 years and 5 months ago. An archived source repository removes the normal path for maintenance and fixes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.5 | — | — |
laravel/framework Version ^9.0 | — | — |
pragmarx/google2fa Version ^8.0 | — | — |
bacon/bacon-qr-code Version ^2.0 | — | — |
web-auth/webauthn-lib Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.