The MIT license and included README make the package easier to evaluate and adopt. Its single registry maintainer and lack of security scanning provide limited support for an authentication component.
32%
Total Score
25
69
83
The package has had only three releases, all concentrated on 11 October 2020, with no releases in the last 12 months. That long release gap is strong evidence of abandonment for a security-sensitive library.
There were zero commits and zero active maintainers in the last three months, consistent with the absence of releases since 2020. For a library handling authentication, this is a major abandonment risk.
Only one registry account has publish access. This is a limited support base, and the repository's user ownership provides no organizational backing to compensate for it.
The repository has one star and no forks, indicating very limited adoption and external scrutiny. Popularity is only supporting evidence, but this provides no meaningful buffer against the stale maintenance record.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a meaningful hygiene gap for an OAuth2 and authentication package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.3 | — | — |
illuminate/auth Version ^8.2 | — | — |
illuminate/http Version ^8.2 | — | — |
firebase/php-jwt Version ^5.0 | — | — |
illuminate/cookie Version ^8.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.