Silex application that provides JSON Web Tokens
68%
Total Score
caution
Usable with caveats: frequent releases help, but recent repository activity and workflow supply-chain hygiene are weak.
The application declares 22 runtime dependencies, creating a relatively broad dependency surface for a small project. The signal provides no evidence that this is unmanaged, so this is a modest transparency and maintenance concern rather than a severe risk.
The repository recorded zero commits and zero active maintainers in the last three months, despite a recent package release. That weakens evidence of ongoing source maintenance and increases abandonment uncertainty.
The project uses Make and Composer, but no security-scanning tool was detected. Build tooling is present, while automated security coverage is not evident.
The repository has no security policy. For an authentication-focused application, this leaves vulnerability reporting and handling less transparent.
The single workflow was fully analyzed with no detected dangerous sinks or audit findings, but all 9 action references are unpinned. That leaves the build exposed to action changes and is a workflow hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slim/psr7 Version ^1.6 | — | — |
sentry/sdk Version ^4.0 | — | — |
filp/whoops Version ^2.5 | — | — |
aura/session Version ^2.1 | — | — |
league/route Version ^4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.