Tests and a matching MIT license provide useful baseline assurance, and the workflow audit found no high-severity issues. The single maintainer, absent security policy, and modest project adoption add uncertainty for a security-sensitive authentication library.
38%
Total Score
33
69
67
This is the package's only release, published over three years ago, with no releases in the last 12 months. That long period without a new version is strong evidence of abandonment risk.
There were no commits and no active maintainers in the last three months, consistent with the package having received no release since 2023. This materially increases maintenance and abandonment risk.
One registry publishing account is consistent with an individually owned repository, so the count alone is not a defect. Combined with zero recent commit activity, it provides no visible backup maintenance capacity.
The registry namespace and repository owner match, and the owner is an individual rather than an organization. This confirms ownership alignment but offers no organizational backing to compensate for inactivity.
The repository has 2 stars, 0 forks, and 1 watcher, indicating limited external adoption. Popularity is supporting evidence rather than a verdict, but it provides little compensating confidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.5 | — | — |
laravel/framework Version ^9.33|^10.0 | — | — |
pragmarx/google2fa Version ^8.0 | — | — |
bacon/bacon-qr-code Version ^2.0 | — | — |
web-auth/webauthn-lib Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.