It has a clear MIT license, repository tests, release notes, and dependency-scanning tooling. The linked repository does not identify the package in its name or README, and it lacks a security policy.
58%
Total Score
75
100
83
67
The latest release was in March 2024, with no releases in the last 12 months and only two releases overall. This indicates limited release maintenance for a library handling authentication.
There were no commits and no active maintainers in the last three months. This weakens evidence of ongoing maintenance, although the repository's recent push prevents treating it as abandoned outright.
The repository name does not match the package name and its README does not mention the package. This creates uncertainty that the linked source repository is specifically maintained for this package.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no external indication of adoption or review.
The repository has no security policy. For an authentication package, the absence of a documented vulnerability-reporting process is a meaningful transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aws/aws-sdk-php Version ^3.261 | — | — |
firebase/php-jwt Version ^6.3 | — | — |
guzzlehttp/guzzle Version ^7.5 | — | — |
illuminate/support Version ^8.0 | — | — |
codercat/jwk-to-pem Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.