Strong tests, release notes, licensing, and build checks support adoption. The project is new and maintenance evidence is still narrow, so longer-term reliability remains unproven.
72%
Total Score
67
100
89
88
This is the first release and the package is 0 days old, so there is not yet enough release history to demonstrate sustained maintenance.
One contributor made all two recent commits, leaving maintenance concentrated in a single person. Organization backing helps provide ownership context but does not show a second active maintainer.
Two commits in the last 3 months show recent activity, but the short observation period and very small commit count provide limited evidence of sustained maintenance.
The repository has no stars, forks, or watchers. For a brand-new release this is limited supporting evidence, not a standalone health failure.
No repository security policy was found. This is a transparency gap for an authentication package, though the repository does perform dependency auditing.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0 | — | — |
lcobucci/jwt Version ^5.5 | — | — |
cycle/database Version ^2.22 | — | — |
componenta/auth Version ^3.0 | — | — |
componenta/clock Version ^1.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.