The repository includes tests, documentation, a matching package name, and clear MIT licensing. No install-time scripts reduce packaging risk, but the code offers little evidence of current compatibility.
42%
Total Score
0
70
50
The package has had no release in about five years and none in the last 12 months, despite 49 historical releases. This is strong evidence of abandonment for a library that integrates with changing framework and authentication ecosystems.
There were zero commits and zero active maintainers in the last three months, consistent with the package's long release gap. This leaves little evidence that defects or compatibility issues are being addressed.
The repository has no security policy. For an authentication library, that is a meaningful transparency gap because it gives users no documented reporting path, although it does not by itself show a security defect.
The assessed release is a release candidate while the registry's latest version is stable 1.0.3, making this specific version less suitable for new adoption. The stable major version provides some compensating maturity evidence.
The workflow audit completed fully and found no untrusted checkout or script-injection path. All four action references are unpinned, and the low-confidence cache-poisoning finding is hygiene rather than a decisive risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
namshi/jose Version ^7.0 | — | — |
lcobucci/jwt Version ^3.2 | — | — |
nesbot/carbon Version ^1.0|^2.0 | — | — |
illuminate/auth Version ^5.1|^6 | — | — |
illuminate/http Version ^5.1|^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.