Risky to adopt: this package has had only one release, with no releases in nearly six years and no recent repository commits. It is not deprecated or archived and has tests, licensing, and organization backing, but the long-standing inactivity makes ongoing maintenance uncertain.
42%
Total Score
50
50
67
83
The package has only one release, published nearly six years ago, with no releases in the last 12 months. This is strong evidence of limited maintenance for a security-sensitive authentication library.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old last push and one-release history, this is the main abandonment concern.
Eight runtime dependencies, including two JWT libraries and several Illuminate components, create meaningful compatibility and maintenance surface area. The profile is plausible for a Laravel authentication package but adds more components to keep current.
There were no new or closed issues or pull requests in the last month, while two pull requests remain open. This suggests little current project activity, though the available issue count is incomplete.
The repository has zero stars, zero watchers, and one fork. Popularity is only supporting evidence, but these very low counters provide little independent evidence of a mature, widely reviewed project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
namshi/jose Version ^7.0 | — | — |
lcobucci/jwt Version ^3.2 | — | — |
nesbot/carbon Version ^1.0|^2.0 | — | — |
illuminate/auth Version ^7 | — | — |
illuminate/http Version ^7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.