Risky to adopt: this authentication package has had no release or repository activity for nearly two years and only two releases. It is licensed, clearly backed by an organization, and not deprecated or archived, but its early version and stalled maintenance make it a liability for new projects.
42%
Total Score
63
100
72
50
There have been only two releases, both within about 5 days of each other, and no releases in the last 12 months despite the package being about 898 days old. That is strong evidence of stalled maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, materially increasing abandonment risk for an authentication dependency.
The package uses a post-autoload-dump lifecycle script, which can run during installation and deserves review, but this signal alone does not show harmful or unusually risky behavior.
There are no open issues or pull requests and no issue or pull-request activity in the last month. While this is not inherently unhealthy, it provides no evidence of an active maintenance community.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little community evidence to offset the inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^6.0|^7.0 | — | — |
illuminate/support Version ^10.0|^11.0 | — | — |
pragmarx/google2fa Version ^8.0 | — | — |
bacon/bacon-qr-code Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.