Tests, a clear MIT license, and organization backing provide useful maintenance foundations. The workflow is basic but has no detected audit findings; its unpinned actions and the lack of security tooling still weaken reproducibility.
58%
Total Score
67
100
78
67
The package has only four releases and none in roughly five years, despite a stable v1.0.3 release. This is strong evidence of a stalled project rather than an actively maintained dependency.
There were zero commits and zero active maintainers in the last three months, consistent with the repository having stopped receiving updates for about five years. This materially raises abandonment risk.
There are two open issues but no new or closed issues and no pull requests in the last month. The small issue load is not severe, but the absence of current activity reinforces the maintenance concern.
The repository has one star and two forks, indicating a very small user and contributor footprint. Popularity is supporting evidence only, but this leaves limited external maintenance capacity.
Composer build tooling is present, but no security-scanning tools were detected. That is a hygiene gap for a security-sensitive 2FA package, though it is not evidence of a defect by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
litstack/litstack Version ^3.1.2 | — | — |
bacon/bacon-qr-code Version ^2.0 | — | — |
pragmarx/google2fa-qrcode Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.