Usable with caveats: the package is licensed, documented, tested, and not deprecated or archived. However, it has had no release for more than a year, no commits in the last three months, and only one maintainer with very little repository adoption.
54%
Total Score
50
50
83
88
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and raising abandonment risk.
The package has eight runtime dependencies, including several Laravel authentication, permissions, impersonation, and social-login components. This is substantial integration surface for a security-sensitive module and increases maintenance exposure, but is not inherently unsafe.
Only one registry account has publish access. This is a limited publishing base and leaves little redundancy if that maintainer becomes unavailable, though registry access alone does not establish actual development activity.
The package has 50 releases since February 2023, but none in the last 12 months; its latest release was more than a year ago. This is a meaningful maintenance concern for an authentication module.
There are no open issues or pull requests and no recent issue or pull-request activity. This may reflect a quiet project, but it also provides no evidence of ongoing community maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/fortify Version ^v1.21.3 | — | — |
illuminate/config Version ^11.0|^12.0 | — | — |
laravel/socialite Version ^5.16 | — | — |
illuminate/contracts Version ^11.0|^12.0 | — | — |
spatie/laravel-permission Version ^6.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.