Tests, documentation, and licensing are in place. The project lacks a security policy and automated security scanning, so maintenance expectations should remain modest.
58%
Total Score
75
100
83
83
This is a young package with one release, published 98 days ago. The short history provides little evidence of sustained maintenance, though the package is not yet old enough to establish abandonment.
The repository had zero commits and zero active maintainers in the last 3 months, despite being only 98 days old. That leaves little evidence of ongoing maintenance after the initial release.
The repository has zero stars, forks, and watchers, indicating limited visible adoption. Popularity is only supporting evidence, so this lowers confidence modestly rather than making the package unsafe by itself.
Composer build tooling is present, but no security-scanning tools were detected. For an authentication package, that is a meaningful maintenance and transparency gap.
The repository has no security policy. Because this package handles authentication and token validation, the absence makes vulnerability reporting and response expectations less clear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/auth Version ^10|^11|^12|^13 | — | — |
illuminate/http Version ^10|^11|^12|^13 | — | — |
firebase/php-jwt Version ^6.3|^7 | — | — |
illuminate/cache Version ^10|^11|^12|^13 | — | — |
guzzlehttp/guzzle Version ^6.5|^7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.