The project has clear documentation, tests in its repository, a changelog, and a matching source repository. Its maintenance and security visibility are weak, with no commits or releases for about four years and no security policy or scanning.
55%
Total Score
0
78
75
The latest release was about four years ago, with no releases in the last 12 months. This is meaningful abandonment risk for a framework integration, despite the package having nine releases overall.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the roughly four-year gap since the last release. This materially raises the chance that compatibility or security issues will go unaddressed.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but this provides no community signal to compensate for the stale maintenance record.
Composer build tooling is present, but no security-scanning tools were detected. That weakens security transparency for an authentication-related package.
The repository has no security policy. For a package handling one-time-password routes, this leaves vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.35 | — | — |
illuminate/http Version ^9.0 | — | — |
illuminate/routing Version ^9.0 | — | — |
illuminate/support Version ^9.0 | — | — |
illuminate/database Version ^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.