The repository includes tests, documentation, and a matching MIT license. However, the release remains a release candidate and shows no recent maintenance or published security policy, making long-term support uncertain.
34%
Total Score
50
70
50
The package is about 7 years and 10 months old, with 41 releases but none in the last 12 months; its latest release was in November 2018. This strongly lowers confidence in ongoing maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the package's long release gap. This is substantial abandonment risk.
The repository has 0 stars, 0 forks, and 0 watchers. Popularity is only supporting evidence, but these values provide no additional evidence of a maintained user base.
The linked repository has no security policy. For an authentication package, that leaves vulnerability reporting and response expectations less transparent.
The assessed version is still marked as a release candidate, despite being the latest version and having a stable major version. That increases compatibility and support uncertainty.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
namshi/jose Version ^7.0 | — | — |
lcobucci/jwt Version ^3.2 | — | — |
nesbot/carbon Version ^1.0 | — | — |
illuminate/auth Version 5.1.* || 5.2.* || 5.3.* || 5.4.* || 5.5.* || 5.6.* || 5.7.* | — | — |
illuminate/http Version 5.1.* || 5.2.* || 5.3.* || 5.4.* || 5.5.* || 5.6.* || 5.7.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.