Frequent releases and a current, non-archived repository support ongoing maintenance. MIT licensing, a package README, and no install-time scripts make adoption clearer.
68%
Total Score
83
94
75
Only one contributor made all 6 commits in the last 3 months, leaving maintenance dependent on a single person despite the repository being owned by an organization.
Composer is used for builds, but no security scanning tools were detected, leaving security checks less transparent than they could be.
The repository has no security policy, so vulnerability reporting and response expectations are not documented.
The single workflow grants top-level write permissions and uses its only action reference without pinning. The audit found no untrusted checkout, script injection, or other concrete workflow finding, so this is a hygiene caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/sanctum Version ^4.0 | — | — |
google/apiclient Version ^2.18 | — | — |
laravel/framework Version ^10.0|^11.0|^12.0|^13.0 | — | — |
laravel/socialite Version ^5.16 | — | — |
iquesters/foundation Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.