The package includes tests, a substantial README, and no install-time scripts. Its five releases landed in one day, followed by no recorded commits for about six months, and the repository has no security policy.
58%
Total Score
25
100
81
83
The repository recorded zero commits and zero active maintainers in the last three months, indicating that development has effectively stopped after the initial publication burst.
The repository is owned by an individual account rather than an organization, and no broader project backing is shown. Combined with zero recent commit activity, this leaves limited visible maintenance capacity.
All five releases were published within one day, and no later release activity is shown across the package's roughly six-month history. This suggests a burst of initial development rather than an established maintenance cadence.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this lowers confidence in project maturity slightly but is not decisive alone.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and maintenance gap for a package handling OAuth credentials, messaging, and webhooks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/sanctum Version ^4.0 | — | — |
guzzlehttp/guzzle Version ^7.8 | — | — |
laravel/framework Version ^10.0|^11.0|^12.0 | — | — |
pusher/pusher-php-server Version ^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.