Repository testing, release notes, and a proper license improve transparency. The lack of a security policy and limited project following still leave maintenance capacity uncertain.
62%
Total Score
50
89
50
Four releases were published in the last 12 months, showing initial release momentum, but the latest registry release was in November 2025 for a package that is 344 days old.
The repository recorded zero commits and zero active maintainers during the last three months, which is a meaningful sign that maintenance has slowed.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but this provides little external evidence of adoption.
No SECURITY.md policy was found, leaving vulnerability reporting and response expectations undocumented for a package used in authentication-related flows.
All 27 analyzed Actions references are unpinned, weakening build reproducibility. The audit also found high-confidence bot-condition findings and a low-confidence cache-poisoning pattern; no untrusted checkout or script-injection sink was found, so these are hygiene concerns rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
illuminate/container Version ^10.0|^11.0|^12.0 | — | — |
illuminate/notifications Version ^10.0|^11.0|^12.0 | — | — |
giggsey/libphonenumber-for-php Version ^8.0|^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.