Risky to adopt for a new project: the package has had no release in about 3 years and 5 months, with no recent repository commits. Tests, a license, and an unarchived repository help, but missing documentation and limited security-maintenance evidence increase abandonment risk.
45%
Total Score
25
100
63
70
The latest release was published about 3 years and 5 months ago, and there were no releases in the last 12 months. The short release history provides little evidence of ongoing maintenance.
There were no commits and no active maintainers in the last 3 months. Combined with the long release gap, this is strong evidence that maintenance has stalled.
The repository has one pull_request_target workflow. No untrusted checkouts or script injection were detected, but this workflow type still warrants review because it can run with elevated repository context.
The package contains no README, which makes integration harder for a library, although repository and package tests are present and provide some compensating project evidence.
The repository is owned by an individual account rather than an organization. This does not establish poor health, but it provides less visible institutional backing for a package already showing stalled activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^9.33|^10.0 | — | — |
claudiodekker/laravel-auth-core Version ^0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.