The package includes a complete source tree, repository tests, a changelog, security policy, and automated dependency scanning. Pinning is weak in the workflows, and the assessed prerelease is less suitable than the available stable line.
68%
Total Score
67
100
94
100
All three recent commits came from one contributor, giving the project a concentrated recent maintenance base. Organization backing provides some handoff capacity, but no second recent contributor is shown.
Only three commits were recorded in the last three months. Recent activity exists, but the pace is light for a security-sensitive authentication library.
The assessed version is a prerelease while the latest available version is stable (v2.9.3). That makes this specific release less appropriate for a new dependency unless its prerelease changes are required.
All three workflows were analyzed without failures and have no untrusted checkout or script-injection findings, but all 11 action references are unpinned. Two low-confidence high-severity cache-poisoning patterns were also reported, warranting workflow hygiene caution rather than a severe conclusion.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
namshi/jose Version ^7.0 | — | — |
lcobucci/jwt Version ^3.2 | — | — |
nesbot/carbon Version ^1.0|^2.0 | — | — |
illuminate/auth Version ^5.1|^6 | — | — |
illuminate/http Version ^5.1|^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.