The release has useful documentation, repository tests, release notes, and no install-time scripts. Maintenance evidence is thin, with only two releases over 783 days and no commits in the last three months.
32%
Total Score
50
75
83
Packagist marks the entire package as abandoned and names laravel/passkeys as its replacement. This is a direct adoption concern beyond a release-specific warning.
The package has only 2 releases over 783 days, with 1 release in the last 12 months and a median interval of about 662 days. The recent release partly offsets the sparse history but does not show active cadence.
The repository recorded 0 commits and 0 active maintainers in the last three months. Although the latest release was published recently, current maintenance capacity is not demonstrated.
No security policy was found in the repository. For an authentication package, the absence reduces vulnerability-reporting transparency.
The single workflow has no untrusted checkout or injection findings, but all 11 action references are unpinned. The missing top-level permissions block is acceptable on its own, while unpinned actions remain a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/auth Version 12.*|13.* | — | — |
illuminate/http Version 12.*|13.* | — | — |
illuminate/config Version 12.*|13.* | — | — |
illuminate/session Version 12.*|13.* | — | — |
illuminate/support Version 12.*|13.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.