The package has a clear README, MIT licensing, repository tests, and a matching organization-backed source repository. Its identity closely resembles laravel/passport despite no overlap or claimed fork relationship, and recent commit activity is absent, so pinning this release requires care.
38%
Total Score
50
75
50
The package is reported as borrowing the identity of the much more established laravel/passport, with borrows_lookalike_identity true; the zero artifact overlap and README distinction do not compensate for that supply-chain confusion risk.
The package is mature at 1,874 days old, but it has only 7 releases and a median release interval of about 348 days, with 1 release in the last 12 months; this reflects a slow maintenance cadence.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, indicating no recent maintenance activity despite the release being available.
The repository has no published security policy, reducing transparency about vulnerability reporting and handling, although this is a documentation gap rather than evidence of an active security problem.
The only workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings. However, all 3 action references are unpinned, leaving a modest build-reproducibility and action-change risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^11.0|^12.0|^13.0 | — | — |
illuminate/pagination Version ^11.0|^12.0|^13.0 | — | — |
laravel-json-api/eloquent Version ^4.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.