Delegated access for AI agents per Laravel IAM: agent registry, delegation grants con consenso step-up, OAuth2 Token Exchange (RFC 8693) con claim act, intersection PDP (utente ∩ agente), audit stream=delegation.
72%
Total Score
100
100
81
75
The manifest declares MIT, while the artifact license file is recognized as Apache-2.0; although a license is present, the mismatch creates uncertainty about the terms of this release.
The package is only 26 days old and has issued 11 releases, with a median interval of about 1 hour 14 minutes. This shows active iteration but leaves little long-term maintenance history.
Composer build tooling is present, but no security-scanning tool was detected. For an authorization-focused package, that is a modest transparency and maintenance gap.
The linked repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented for a package handling delegated access.
Both workflows were analyzed without high-confidence audit findings, but all 3 action references are unpinned and one workflow grants top-level write permissions. These are avoidable supply-chain and permission-hygiene weaknesses, though not severe on their own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/oauth2-server Version ^9.0 | — | — |
padosoft/laravel-iam-server Version ^1.27 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
padosoft/laravel-iam-contracts Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.