Say goodbye to passwords and sign in via PIN instead.
8%
Total Score
critical
Unfit to use: the package is deprecated and its source repository is archived.
Packagist marks the entire package as abandoned and names empuxa/laravel-totp-login as its replacement. This is a direct indication that new dependencies should not adopt this package.
The latest release was published on April 17, 2024, and there have been no releases in roughly two years. Combined with the archived repository, this indicates abandonment rather than a merely slow cadence.
The repository recorded zero commits and zero active maintainers in the last three months. This supports the abandonment concern, despite the package having a stable release history.
The linked repository is archived, with its last push on April 19, 2024. An archived source repository signals that maintenance and issue response have ended.
All 11 analyzed action references are unpinned, and the audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow. These are secondary maintenance and workflow-hygiene concerns, not the main reason to reject the release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version ^9.52|^10.0|^11.0 | — | — |
illuminate/events Version ^9.52|^10.0|^11.0 | — | — |
illuminate/routing Version ^9.52|^10.0|^11.0 | — | — |
illuminate/support Version ^9.52|^10.0|^11.0 | — | — |
illuminate/contracts Version ^9.52|^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.