The package is documented and its repository matches the package, but it has no tests or security policy. Its single release and no commits for more than three years make future maintenance uncertain.
43%
Total Score
0
75
75
This is the package's only release, published more than three years ago, with no releases in the last 12 months. That is strong evidence of limited ongoing maintenance for a framework integration package.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no activity since December 2022. No provided signal compensates for this prolonged inactivity.
The artifact contains an MIT declaration and a license file, but the detected license text is Apache-2.0, creating an unresolved mismatch about the release's licensing terms. The repository also has a license file, but it does not remove the artifact-level inconsistency.
The linked repository has no security policy. For a package providing authentication, permissions, migrations, and administrative endpoints, this reduces transparency around vulnerability reporting.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/sanctum Version ^2.4 | — | — |
spatie/laravel-permission Version ~3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.