The package is MIT-licensed, stable, actively released, and has a modest dependency set. Repository security coverage is limited, and the linked repository does not clearly identify this package.
68%
Total Score
75
100
78
83
The artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the absent README is a minor transparency and consumer-documentation gap for a reusable PHP library.
The repository recorded zero commits and zero active maintainers in the last three months. Frequent registry releases partly offset this, but the source activity still leaves maintenance continuity uncertain.
The repository name does not match the package name, and README mention status is unavailable. Organization backing makes a monorepo or sub-package plausible, so this is a limited ownership-clarity concern rather than a severe mismatch.
The repository has zero stars and forks and only two watchers. Popularity is supporting evidence rather than a verdict, but this provides little independent evidence of community adoption.
Composer is used for the build, but no security-scanning tool was detected. This is a hygiene gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/sanctum Version >=3 | — | — |
laravel/framework Version >=10 | — | — |
pragmarx/google2fa Version >=9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.