It has no tests, security scanning, or security policy, and no commits or releases for about two years. The small, single-person project also offers limited evidence of ongoing support.
38%
Total Score
50
100
75
83
The package borrows the identity of the far more established laravel/sanctum, with borrows_lookalike_identity true and no self-described fork or integration evidence. This is strong evidence that consumers could choose the wrong package.
Only one registry publishing account is listed. The repository is user-owned rather than organization-backed, so there is little visible redundancy in publishing capacity.
The package has four releases, all clustered around its first release about two years ago, with no releases in the last 12 months. That provides weak evidence of continued maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the absence of recent registry releases. This raises abandonment risk.
Composer build tooling is present, but no security scanning tools are configured. The missing scanning is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.