The package includes extensive tests, a substantial README, and no install-time scripts. Its license declaration conflicts with the detected license text, while the repository shows no commits in the last three months. Pin this version only after resolving the licensing question.
62%
Total Score
50
81
75
The manifest declares LGPL-3.0-or-later, but the artifact license file was detected as GPL-3.0; the presence of license files provides transparency but does not resolve the mismatch.
The package and repository are owned by the same individual account rather than an organization, so the single registry maintainer represents a thin project backing model.
The repository recorded zero commits and zero active maintainers in the last three months, which weakens evidence of ongoing maintenance even though the registry shows recent releases.
The repository has two stars and one fork, indicating limited adoption evidence; this is supporting context rather than a health verdict, and the package has other maintenance evidence.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a package that generates authentication-related application code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.