The project has limited oversight and documentation, although it remains unarchived and uses a stable release line. Its workflow uses two unpinned actions and one archived action, adding avoidable maintenance risk.
55%
Total Score
50
100
88
67
The package and repository are owned by an individual account rather than an organization, so the single-person maintenance model provides limited visible backing.
There have been no releases in the last 12 months, and the latest release was about 15 months ago; the 25-release history shows prior activity but does not offset the current pause.
The repository had zero commits and zero active maintainers in the last 3 months, reinforcing the broader evidence that maintenance has stopped recently.
Composer is used as the build tool, but no security scanning tooling is present, leaving security maintenance less visible.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities in an authentication package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/sanctum Version ^3.3|^4.0 | — | — |
laravel/framework Version ^10.29||^11.0|^12.0 | — | — |
laravel/jetstream Version ^4.0|^5.0 | — | — |
spatie/laravel-permission Version ^6.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.