The package has clear documentation, tests, release notes, and a matching source repository. Its short history and single-contributor activity leave limited evidence of long-term maintenance, while the repository has no security policy or scanning tools.
63%
Total Score
50
100
88
75
The source repository is owned by a personal account rather than an organization, so the concentrated contributor activity is not offset by visible organizational backing.
This is a young package with one release over about four months and no established release cadence, so long-term maintenance is not yet demonstrated.
One contributor made all two recent commits, so maintenance depends entirely on a single individual with no demonstrated handoff capacity.
Only two commits were recorded in the last three months, showing some recent activity but limited maintenance capacity for a package with broad functionality.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-process gap for a package handling authentication, messaging, and file attachments.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/sanctum Version ^4.0|^5.0 | — | — |
laravel/framework Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.