Tests, a detailed README, and matching MIT licensing support adoption. The single-maintainer project has made no commits or releases for about a year, and no security tooling is reported.
62%
Total Score
67
86
75
One registry maintainer creates a thin publishing base, although the linked repository is owned by an organization, which provides some backing. This is a moderate resilience concern rather than a severe risk.
The package has seven releases, but all were published in a short burst around September 2025 and none appeared in the following 12 months. This suggests stalled maintenance rather than an established release cadence.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the long release gap. No provided activity signal compensates for this pause.
Composer build tooling is present, but no security-scanning tools are reported. The missing scanning is a hygiene gap for a package handling authentication and identity APIs.
The repository has no documented security policy, leaving vulnerability reporting and response expectations unclear for an authentication and identity-integration package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
illuminate/support Version ^11.0|^12.0 | — | — |
illuminate/contracts Version ^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.