The package has a declared MIT license, release notes for this version, and no install-time scripts. Its very short README and absent security policy reduce transparency, while recent work remains concentrated in one contributor.
62%
Total Score
50
50
93
83
The release declares 10 runtime dependencies and no development dependencies. This creates a relatively broad runtime update surface for a focused module, though the dependencies are relevant Laravel and Telegram components.
One contributor made all 2 commits in the last 3 months, leaving maintenance dependent on a single active contributor.
Only 2 commits were recorded in the last 3 months, indicating limited recent source activity despite the frequent registry releases.
Composer is used as the build tool, but no security scanning tool was detected. The missing scanning is a modest transparency and hygiene gap rather than evidence of unsafe code.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a package handling authentication and Telegram integrations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/sanctum Version ^4.3 | — | — |
laravel/socialite Version ^5.24 | — | — |
irazasyed/telegram-bot-sdk Version ^3.15 | — | — |
spatie/laravel-activitylog Version ^4.10 | — | — |
vicky-project/users-module Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.