The small organization-backed project has a clear license, documentation, repository tests, and no install-time scripts. Its release cadence is sparse, recent commit activity is absent, and the workflow has script-injection exposure with all actions unpinned.
62%
Total Score
67
100
88
83
Only one registry account has publish access, but the repository is owned by an organization, which provides some backing and makes a short registry maintainer list less concerning.
The package has only four releases over about 948 days, with one release in the last 12 months and a median interval of about 360 days; this indicates a slow maintenance cadence.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful sign of currently limited maintenance capacity.
Composer build tooling is present, but no security-scanning tool was detected, leaving security checks less visible than they could be.
The repository has no dedicated security policy, although the README provides a security contact. The missing formal policy is a minor transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/passport Version ^13.0 | — | — |
illuminate/support Version ^11.35 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.