The project is only three days old, despite 18 releases, so its long-term stability is unproven. Active commits, two balanced contributors, release notes, tests in the repository, and organization backing provide meaningful support.
72%
Total Score
100
86
50
The package runs a post-autoload-dump install lifecycle script. This deserves some review because install-time code executes automatically, but the signal alone does not show unsafe behavior.
The package is only 3 days old but already has 18 releases, with a median interval of about 29 minutes. This shows active iteration, but provides little evidence of long-term stability.
No security policy is present in the repository. For a package handling GitHub sign-in, tokens, and agent sessions, this is a transparency gap.
Version v0.6.10 is not a stable major release, although it is not marked as a prerelease and recent releases contain no prereleases. The 0.x version still signals an evolving API.
The single workflow has read-only permissions and no audited dangerous findings, but all 21 action references are unpinned. That leaves the build exposed to moving action versions and is a workflow hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/mcp Version ^1.0 | — | — |
laravel/sanctum Version ^4.3.1 | — | — |
laravel/socialite Version ^5.31.0 | — | — |
livewire/livewire Version ^4.2.0 | — | — |
illuminate/contracts Version ^13.23.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.