The repository has no security policy and its README does not mention this package, weakening transparency and ownership confidence. The MIT declaration and organization backing help, but do not offset the release and readiness concerns.
18%
Total Score
100
50
50
The package includes a README and a GitHub release for this version, but the README explicitly says the package is not ready for production. The absence of tests is normal packaging practice and is not counted against it.
The latest release was published in August 2017, with no releases in the last nine years. This indicates severe abandonment risk for a package intended to handle API authentication.
The repository name matches the package, which supports ownership, but its README does not mention the package. That mismatch leaves some uncertainty about how the published artifact is documented.
The repository is not archived, but it was last pushed in June 2018 and has had no recent repository activity shown here. That partially preserves access while still indicating prolonged inactivity.
The linked repository has no security policy. For an authentication package, this is a meaningful transparency and vulnerability-reporting gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tymon/jwt-auth Version 0.5.* | — | — |
google/apiclient Version ^2.0 | — | — |
facebook/graph-sdk Version ^5.6 | — | — |
spatie/laravel-fractal Version ^4.01 | — | — |
spatie/laravel-permission Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.