The package is clearly identified and documented, with an MIT license, a matching repository, and release notes for this version. Its lack of security scanning and single-person publishing base make long-term maintenance less reassuring.
58%
Total Score
50
83
75
One registry maintainer creates a thin publishing base. The linked repository is user-owned rather than organization-backed, so there is no provided evidence of broader institutional support.
Only two releases exist, both about 13 months ago, with no releases in the last 12 months; this is a meaningful sign of limited ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, so current maintenance capacity is not demonstrated.
The repository has 1 star, 0 forks, and 0 watchers. Popularity is only supporting evidence, but these counts provide little external evidence of adoption or review.
Composer build tooling is present, but no security scanning tools were detected; for an authentication package, that is a relevant transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/auth Version ^9.0|^10.0|^11.0|^12.0 | — | — |
paragonie/paseto Version ^v3.0 | — | — |
illuminate/support Version ^9.0|^10.0|^11.0|^12.0 | — | — |
illuminate/contracts Version ^9.0|^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.