The package is licensed, includes a consumer README, repository tests, and Dependabot scanning. Its workflows contain high-confidence bot-condition and unpinned-image findings, while the lack of a security policy reduces transparency.
12%
Total Score
0
60
50
The package has had no release in about four years, with no releases in the last 12 months. Combined with the archived repository, this strongly indicates that maintenance has stopped.
The repository recorded zero commits and zero active maintainers during the last three months. This confirms there is no recent maintenance activity to offset the older release history.
The linked repository is archived, and its last push was about three years ago. An archived source project is a severe abandonment risk for a dependency.
The repository has no security policy. That leaves vulnerability reporting and response expectations unclear, which matters for an authentication package.
All eight analyzed action references are unpinned, and the audit found high-confidence bot-condition and unpinned-image issues. The pull_request_target workflow also has top-level write permissions, creating avoidable workflow hygiene and supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tymon/jwt-auth Version dev-develop | — | — |
filament/filament Version ^2.0 | — | — |
illuminate/support Version ^9.20 | — | — |
illuminate/contracts Version ^9.0 | — | — |
lorisleiva/laravel-actions Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.