The MIT license, complete README, matching repository, and lack of install-time scripts provide useful transparency. However, the source has received no commits or releases for more than 10 years, with no security policy and no recent contributor activity.
35%
Total Score
25
50
78
75
The package is more than 10 years old and has had no releases in the last 12 months. Its six releases were concentrated on the original publication date, indicating no continuing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old last push and release history, this is strong evidence of abandonment risk.
Six runtime dependencies, including Laravel components, Guzzle, and an OAuth client, create a meaningful dependency surface for an authentication library, but the signal does not show that the profile is excessive or unsafe.
The repository is owned by an individual user rather than an organization, and the package has one registry maintainer. This provides little visible institutional backing for a long-unmaintained library.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these values provide no meaningful community or adoption cushion.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ~5.0 | — | — |
guzzlehttp/guzzle Version ~5.0|~6.0 | — | — |
illuminate/support Version ~5.0 | — | — |
illuminate/contracts Version ~5.0 | — | — |
league/oauth1-client Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.