The MIT license, focused dependencies, README, and tests make adoption clear. Maintenance evidence is weak: releases and commits stopped about 18 months ago, with one registry maintainer and no security policy.
58%
Total Score
50
100
90
75
One registry maintainer creates a thin publishing base and increases continuity risk if that individual becomes unavailable. The linked repository is user-owned, so organization backing does not offset this concern.
The package has 8 releases, but all activity ended about 18 months ago and there were no releases in the last 12 months. The early burst of releases does not compensate for the prolonged absence of updates.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long release gap. This is meaningful abandonment risk for a package handling authentication integration.
The repository has no security policy. That weakens vulnerability-reporting transparency, although it is a secondary concern compared with the maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^9.0|^10.0|^11.0 | — | — |
ory/kratos-client-php Version ^1.3.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.