SPID authentication for Laravel through AAC Trentino (OpenID Connect with PKCE)
68%
Total Score
caution
A same-day project with no recorded recent commits and all workflow actions unpinned needs caution.
The package is only 0 days old, with four releases published within the same day. That shows active initial publishing but provides too little history to establish durable maintenance.
The repository records 0 commits and 0 active maintainers in the last 3 months, although the release was pushed shortly before collection and recent pull requests show activity. This leaves maintenance capacity insufficiently demonstrated.
All 12 of 12 analyzed action references are unpinned, which weakens build reproducibility. The workflows use read-only permissions, have no untrusted checkouts or script-injection findings, and the audit completed fully, limiting this to a hygiene caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/log Version ^12.69|^13.30 | — | — |
illuminate/auth Version ^12.69|^13.30 | — | — |
illuminate/http Version ^12.69|^13.30 | — | — |
illuminate/view Version ^12.69|^13.30 | — | — |
illuminate/cache Version ^12.69|^13.30 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.