A five-star project with one registry maintainer has limited visible adoption and resilience. The stable release history, tests, MIT licensing, and clean workflow audit provide useful counterweight, though the actions are not pinned.
62%
Total Score
63
100
89
83
Only one account has registry publishing access, leaving limited apparent publishing redundancy. The linked project is user-owned rather than organization-backed, so no organizational compensation is shown.
The registry namespace and repository owner match, but the owner is an individual user rather than an organization, so there is no visible organizational backing to offset the thin maintainer base.
There were zero commits and zero active maintainers in the last three months, despite the latest release being recent. This is direct evidence of currently limited maintenance activity.
The repository has only 5 stars, 1 fork, and 1 watcher, which indicates a small user base and limited external validation. Popularity is supporting evidence, so this is a modest concern rather than a decisive risk.
Composer build tooling is present, but no security scanning tools were detected. For a small package this is a hygiene gap, not severe evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
apereo/phpcas Version ^1.6.2 | — | — |
laravel/socialite Version ^3.0|^4.0|^5.0 | — | — |
illuminate/support Version ^5.6|^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.