This release is not a safe dependency for new projects: the linked repository is archived, has had no commits or active maintainers in the last 3 months, and its own README states that the package is no longer maintained, should not be used in new projects, and contains known unfixed authentication and two-factor issues. The package is licensed, has a stable version and tests, and does not use install-time scripts, but those positives cannot compensate for explicit abandonment and unresolved correctness limitations.
15%
Total Score
33
100
61
90
The artifact includes a README and tests, but the README explicitly marks the package as archived and documents known unfixed issues, including incorrect database guidance and completely untested two-factor authentication.
The repository recorded 0 commits and 0 active maintainers over the last 3 months, consistent with the archived status and lack of ongoing maintenance.
The linked repository is explicitly archived, which is a severe abandonment risk for an authentication package and indicates that future fixes should not be expected.
Only one registry maintainer is listed; this is a thin publishing base, and the individual ownership context provides no compensating organizational backing.
The repository is owned by an individual account rather than an organization, so the single-owner context offers limited evidence of institutional maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/fortify Version ^1.24 | — | — |
livewire/livewire Version ^4.0 | — | — |
illuminate/support Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.