The project has tests, a substantial README, a changelog, and an MIT license. Its single release and sole active contributor leave limited evidence of long-term maintenance, while the security package lacks a security policy and pins none of its two workflow actions.
65%
Total Score
67
100
89
67
This is the package's first release, published today, so there is no release track record or demonstrated long-term maintenance yet.
One contributor made 100% of the five recent commits. That concentration creates a meaningful continuity risk, partly softened by the repository being owned by an organization.
Five commits occurred in the last three months, showing current activity, but all activity came from one active maintainer and therefore provides limited maintenance depth.
Composer build tooling is present, but no security-scanning tool was detected. For a package handling account lockouts, that is a modest transparency and maintenance gap.
The repository has no security policy. This is a relevant gap for a package explicitly concerned with authentication and account recovery, though it is not evidence of unsafe code by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/auth Version ^10.0|^11.0 | — | — |
illuminate/support Version ^10.0|^11.0 | — | — |
illuminate/database Version ^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.