Generation and control of jwt token
38%
Total Score
unhealthy
Risky: no maintenance since 2022 and the linked repository does not identify this package.
The package has five releases, but its latest release was in June 2022 and it has had no releases in the last 12 months. This indicates substantial abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no activity since June 2022.
The package includes a README, but it is only 13 characters long and provides little consumer documentation. The absence of tests and a changelog in the artifact is normal packaging practice and is not a concern by itself.
The linked repository name does not match the package name, and its README does not mention the package. That weakens confidence that the repository is the package's maintained home.
The repository has no security policy, which is a meaningful transparency gap for a package handling JWT tokens. No provided signal compensates for that missing disclosure process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.