Healthy and reasonable to depend on, with a few maintenance and transparency caveats. It has a long release history, current commits from two contributors, tests, documentation, and no deprecation or risky workflow findings; the missing security policy and inactive issue queue reduce confidence.
78%
Total Score
75
100
88
80
The source repository is owned by an individual rather than an organization, so maintenance depends more directly on that person. This is partly offset by recent activity from two contributors and the package's established history.
The repository has 57 open issues and no issues or pull requests were closed or merged in the last month. This suggests that issue maintenance may be slow and is a real, though not severe, adoption caveat.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning coverage lowers transparency around automated security checks.
No repository security policy was found. For an authentication package, the lack of a documented vulnerability-reporting process is a meaningful transparency gap.
The repository workflow does not declare top-level token permissions. Although no write permissions were detected, explicit least-privilege declarations would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
pragmarx/google2fa-qrcode Version ^1.0|^2.0|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.