The package has a clear README, MIT licensing, tests in its repository, and automated security tooling. Its workflows still need tightening, and the small project footprint limits confidence in long-term support.
42%
Total Score
63
100
88
67
The latest release was over three years ago, with no releases in the last 12 months; four releases were published over a short initial period, indicating strongly stalled maintenance.
The repository had zero commits and zero active maintainers in the last three months, consistent with the release history showing prolonged inactivity.
There are no new or closed issues and no merged pull requests in the last month; two open pull requests provide little evidence of active maintenance.
No security policy is present, leaving vulnerability reporting and response expectations undocumented for a package that handles authentication and impersonation.
All 12 action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow; the pull_request_target trigger has no untrusted checkout or script-injection sink, so this is a hygiene and review concern rather than a standalone critical risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^9.0 | — | — |
lab404/laravel-impersonate Version ^1.7 | — | — |
spatie/laravel-package-tools Version ^1.13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.