The project has active recent commits, release notes, tests, and a license. Its two-person contributor base is heavily concentrated, and the linked repository does not clearly identify this package; verify the source before adopting.
61%
Total Score
67
70
50
The repository name does not match the package name, and its README does not mention the package. That creates a meaningful risk that the published package is linked to the wrong project or is piggy-backing on another repository.
The repository is owned by an individual rather than an organization, so there is no demonstrated organizational handoff capacity to offset the concentrated contributor activity.
The package is only 50 days old but has 24 releases, with a median interval of about one day. This shows active iteration but limited long-term maintenance history and a potentially fast-changing API.
Two contributors are active, but one accounts for about 86% of recent commits. This leaves maintenance dependent on one person despite the recent activity.
The linked repository has no security policy. For an authorization package, that reduces transparency around reporting and handling security issues, although it does not by itself show an active defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/auth Version ^11.0|^12.0|^13.0 | — | — |
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/routing Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.