This is a usable but relatively young package with a healthy current activity profile: it is not deprecated or archived, has 22 releases over 91 days, and the repository recorded 25 commits from three active contributors in the last three months. The organization-owned repository provides some maintenance backing despite the registry having one publisher account. Adoption carries meaningful hygiene and maturity concerns because the artifact and repository contain no tests or changelog, the repository has no security policy or security scanning, and 92% of recent commits come from one contributor. The package is MIT-licensed, has no install-time lifecycle scripts, uses a modest runtime dependency set, and its repository explicitly mentions the package, which offsets some transparency concerns. Depend on it only after reviewing its authentication and migration behavior and adding project-level testing and monitoring.
72%
Total Score
80
100
78
90
Only one registry account has publish access, which is a concentration risk, but the repository is owned by an organization, providing some capacity for maintenance handoff. This is therefore a caution rather than a severe risk.
A substantial README and GitHub Releases are present, but both the artifact and repository lack tests and a changelog. For an authentication package, the absence of repository tests is a genuine maintenance and regression-risk gap.
The package is young at 91 days but has 22 releases, including 21 in the last 12 months, with a median interval of about 11 hours. This demonstrates active iteration but also indicates a rapidly changing project with limited long-term history.
One contributor made 92% of the 25 recent commits, creating a concentrated bus-factor risk. The organization-owned repository and two additional active contributors partly compensate, so this remains caution rather than danger.
The repository has zero stars, forks, and watchers. This limits external validation and community support, but popularity is supporting evidence rather than a health verdict, especially for a young package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/passport Version ^12.0|^13.0 | — | — |
laravel/framework Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.