It has a clear MIT license, substantial documentation, and package/repository naming alignment. The project also lacks security-policy documentation and recent activity, leaving little evidence of ongoing support.
8%
Total Score
50
50
50
Packagist marks the entire package as abandoned, with no replacement provided. Package-level deprecation is a severe warning against taking a new dependency.
There have been no releases in the last 3 years and 2 months, despite a prior median release interval of about 28 days. This supports the abandonment concern.
The linked repository is archived, and its last push was about 3 years and 2 months ago. This strongly indicates the project is no longer maintained.
The repository had no commits and no active maintainers in the last 3 months. Together with the archived state, this provides no evidence of current maintenance.
The repository has no security policy or documented security contact. This is a transparency gap for an OAuth2 authentication package, although it is secondary to the package being abandoned.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.7.0 | — | — |
lcobucci/jwt Version ^5.0.0 | — | — |
illuminate/auth Version ^10.0.0 || ^11.0.0 | — | — |
illuminate/http Version ^10.0.0 || ^11.0.0 | — | — |
symfony/console Version ^6.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.