It has a long release history, clear licensing, tests, release notes, and a source repository that matches the package. The single-maintainer project, absent security policy, and inactive recent commits leave meaningful maintenance risk.
68%
Total Score
75
100
94
50
No commits and no active maintainers were recorded in the last three months. Although a recent release and repository push provide some counterevidence, this still indicates a recent pause in development activity.
Composer is used for builds, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.
The repository has no published security policy. For an authentication middleware package, that weakens the documented process for reporting and handling security issues.
The only workflow was fully analyzed with no detected sinks or high-confidence audit findings, and it has no top-level write permissions. However, both action references are unpinned, leaving the workflow exposed to dependency drift.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.