The package is licensed, recently released, and has a clear repository match. Its small audience and limited project safeguards leave more maintenance risk than mature alternatives.
63%
Total Score
63
100
89
67
Only one registry account can publish the package. This is consistent with a small project but leaves limited publishing redundancy.
The repository is owned by an individual user rather than an organization, so there is no visible organizational handoff capacity to offset contributor concentration.
One contributor made all 6 commits in the last 3 months, creating a high single-maintainer dependency with no active second contributor shown.
The repository has 0 stars, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these counts provide little external validation.
Composer is used for builds, but no security scanning tools were detected, leaving automated vulnerability checks absent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mishal/jwt Version ^1.0 | — | — |
colbeh/logs Version ^1.0 | — | — |
colbeh/access Version ^1.2 | — | — |
kavenegar/php Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.