Clear documentation and no install-time scripts reduce adoption and supply-chain friction. The small artifact and absent security policy leave less evidence than a larger project, but recent releases and shared ownership offset that.
88%
Total Score
100
100
94
75
Composer build tooling is present, but no security-scanning tool was detected; this is a modest transparency and hygiene gap rather than a severe dependency risk.
The linked repository has no security policy, which reduces clarity about vulnerability reporting and response expectations.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-511207 socialiteproviders/apple is vulnerable to Cross-Site Request Forgery (CSRF) in versions 0.0.1 - 5.12.0. | 0.0.1 - 5.12.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^4.1.5 || ^5.0.0 | — | — |
lcobucci/clock Version ^2.0 || ^3.0 | — | — |
firebase/php-jwt Version ^7.0 | — | — |
socialiteproviders/manager Version ^4.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.