The package includes tests, a substantial README, matching source, and a clear Apache-2.0 license. Its repository has no security policy or scanning, leaving maintenance and security practices less transparent.
58%
Total Score
67
75
Only three releases exist, with the latest published in March 2023 and none in the last 12 months; this long inactivity raises abandonment risk despite the initially regular 19-day median interval.
The repository has zero stars and forks and only one watcher, providing little supporting evidence of a broad or active user base. Popularity is secondary, but this reinforces the maintenance concern.
Composer build tooling is present, but no security-scanning tools are reported, leaving a relevant transparency and maintenance gap for an authentication library.
The repository has no security policy, reducing clarity about vulnerability reporting and response for a package handling OpenID Connect authentication.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ~4.1 | — | — |
lcobucci/clock Version ^2 | — | — |
web-token/jwt-core Version ^3 | — | — |
cse/helpers-session Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.