The repository includes tests, a changelog, and release notes, while the package is licensed and not deprecated or archived. Its workflow leaves all three actions unpinned and the repository has no security policy.
55%
Total Score
50
92
50
One registry maintainer publishes the package, and the repository is owned by that same individual. This is a thin maintainer base with limited visible continuity capacity.
The package has had no release in the last 12 months, despite six releases overall, and its latest release was about 18 months ago. This is meaningful abandonment risk for a relatively young package.
The repository recorded zero commits and zero active maintainers over the last three months, providing no evidence of ongoing maintenance. The existing tests and changelog provide some maturity evidence but do not offset the inactivity.
The repository has no security policy. For an authentication package, this weakens vulnerability-reporting transparency and is a genuine maintenance concern.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all three action references are unpinned, leaving the build exposed to changing upstream action code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^6.10 | — | — |
illuminate/console Version ^10.0|^11.0|^12.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.