The package has clear documentation, tests, and release notes, while its security process is limited and workflow actions are unpinned. Its 0.x status calls for normal version-upgrade testing.
68%
Total Score
67
100
81
83
The repository is owned by a user account rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.
The package is young at 64 days with four releases and a median interval of about 29 days, showing active early maintenance but limited long-term evidence.
All 24 recent commits came from one contributor, leaving maintenance dependent on a single person and increasing continuity risk.
Composer build tooling is present, but no security-scanning tools were detected, leaving a meaningful security-process gap for an authentication package.
Version v0.3.1 is not a stable major release, so API or compatibility changes remain more likely than for a mature 1.x package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kornrunner/keccak Version ^1.1 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
stephenhill/base58 Version ^1.1|^2.0 | — | — |
simplito/elliptic-php Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.