The repository includes tests, documentation, a matching package name, and a clear MIT license. Its workflow has a low-confidence cache-poisoning warning, while the missing security policy reduces transparency; pin this release only if you can accept its maintenance risk.
38%
Total Score
0
83
50
The latest registry release was in July 2021, about 5 years ago, and there were no releases in the last 12 months. The package has a substantial 49-release history, but the prolonged pause is a serious maintenance concern.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long gap since the latest release. This provides no evidence of current maintenance capacity.
The repository has no security policy. For an authentication package, the absence of a documented vulnerability-reporting process is a meaningful transparency and maintenance concern.
The only workflow was fully analyzed and has no untrusted checkout or script-injection trigger, but all 4 action references are unpinned. A low-confidence cache-poisoning finding is hygiene evidence rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
namshi/jose Version ^7.0 | — | — |
lcobucci/jwt Version ^3.2 | — | — |
nesbot/carbon Version ^1.0|^2.0 | — | — |
illuminate/auth Version ^5.1|^6 | — | — |
illuminate/http Version ^5.1|^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.