Risky to adopt without careful review: the package has a solid repository with tests, release notes, and recent source activity, but it has no license and is flagged as borrowing the identity of the much more established spatie/laravel-login-link package. Registry releases have also stopped since April 2023.
45%
Total Score
100
67
50
The package is reported to borrow the identity of spatie/laravel-login-link, which has far more downloads and stable releases; although artifact overlap is zero, this naming signal creates a serious risk that consumers may choose the wrong package.
The repository has one pull_request_target workflow, which can require careful review because it runs with elevated event context, but no untrusted checkout or script-injection patterns were detected.
No declared license or license file was found in the package or repository, leaving the terms for using and redistributing this dependency unclear.
The package has five releases, but its latest registry release was about 3 years and 5 months ago, with no releases in the last 12 months; this weakens confidence in ongoing compatibility maintenance.
The repository has no security policy, reducing transparency for vulnerability reporting, though this is not by itself evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^9.0|^10.0 | — | — |
spatie/laravel-mailcoach Version ^6.18 | — | — |
symfony/sendinblue-mailer Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.