It includes a clear license, substantial documentation, tests, and release notes, with an organization-backed, correctly matched repository. The remaining concern is operational upkeep and workflow reproducibility rather than missing project structure.
61%
Total Score
75
90
50
The package has five releases, but none in the last 12 months despite a median interval of about 15 days earlier in its history. This suggests a substantial slowdown in publishing activity.
The repository recorded zero commits and zero active maintainers in the last three months, indicating no recent development activity. This is a meaningful maintenance concern, though the repository is not archived.
No security policy was found in the linked repository. For an authentication component, this is a transparency gap because users have no documented process for reporting vulnerabilities.
Both workflows were fully analyzed with no detected injection or high-severity findings, but all 17 action references are unpinned. That weakens build reproducibility and leaves action versions floating.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
nyholm/psr7 Version ^1.8 | — | — |
ramsey/uuid Version ^4.7 | — | — |
symfony/yaml Version ^6.4 || ^7.0 | — | — |
nesbot/carbon Version ^3.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.