The release is small and has no commits in the past three months, although a recent registry release and organization-owned repository provide some continuity. MIT licensing, a matching repository, and minimal dependencies are solid foundations, but the identity concern makes adoption risky.
43%
Total Score
75
100
83
83
The package is reported to borrow the identity of laravel/sentinel, which has about 6,015,603 monthly downloads versus 28 for this package. The lack of artifact overlap does not offset the explicit identity-borrowing signal, so consumers may have intended to install the established package instead.
The package has existed for about 7 years with 15 releases and one release in the past year. Its latest release is recent, though the low recent cadence limits evidence of active maintenance.
The repository recorded zero commits and zero active maintainers in the past three months. The release and repository were updated recently, which partly offsets abandonment concerns but does not show ongoing development capacity.
The linked repository has no security policy. This is a transparency gap, though the package is small and the repository reports security scanning through Codacy.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.