The repository has no recent commits or automated security scanning, and registry publishing is handled by one maintainer. A README, matching source repository, MIT declaration, and non-archived repository provide useful transparency but do not offset the lack of demonstrated ongoing maintenance.
45%
Total Score
25
75
50
This is the package's only release, published over a year ago, with no releases in the last 12 months. That leaves little evidence of sustained maintenance for a package handling authentication scaffolding.
The repository recorded no commits and no active maintainers in the last three months. The non-archived status is reassuring, but it does not show that maintenance is continuing.
Only one registry account has publish access. The repository is user-owned rather than organization-backed, so there is no provided evidence of a broader publishing or maintenance base.
Composer build tooling is present, but no security scanning tools were detected. This is a meaningful transparency and maintenance gap for authentication-related software.
The repository has no security policy. For a package providing registration, password, email verification, and two-factor authentication scaffolding, this weakens the project's maintenance and disclosure transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ^2.10.1 | — | — |
laravel/fortify Version ^1.26 | — | — |
laravel/framework Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.