Clear README, tests, licensing, and steady releases provide useful transparency. There is no security policy, so maintenance and disclosure expectations are less clear.
42%
Total Score
75
100
81
75
The package borrows the identity of laravel/sanctum, with an explicit lookalike-identity match, even though artifact overlap is 0 and the README does not identify it as a fork. Consumers may have intended the established package instead.
The repository recorded zero commits and zero active maintainers in the last three months. That weakens confidence in ongoing maintenance, even though the registry shows recent releases.
The repository has 0 stars and 3 forks. This is limited adoption evidence, but popularity is supporting context and does not outweigh the package's release history and project backing.
The linked repository has no security policy. That is a transparency and vulnerability-reporting gap for a maintained library, although it does not by itself show unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel-enso/core Version ^12.0 | — | — |
laravel/framework Version ^7.0|^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
laravel-enso/helpers Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.