The package includes tests, a changelog, and no install-time scripts. Its sole registry maintainer, absent security policy, and conflicting license evidence provide little transparency around an otherwise inactive project.
28%
Total Score
0
50
75
The latest release was about 5 years ago, with no releases in the last 12 months and only three releases overall. This is strong evidence of abandonment for a dependency that may need ongoing compatibility fixes.
The repository recorded zero commits and zero active maintainers during the last 3 months, consistent with the package having been inactive since April 2021. No provided maintenance signal compensates for this gap.
The artifact declares MIT, but the detected license text is Apache-2.0 despite license files being present. The mismatch creates a real licensing uncertainty even though the release is not unlicensed.
The linked repository name does not match the package name, and its README does not mention the package. That weakens confidence that the repository is the package's genuine project home.
The repository has no security policy. For an authentication and JWT package, this is a meaningful transparency gap because consumers have no documented vulnerability-reporting process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^3.3 | — | — |
phpdocumentor/reflection Version ^4.0 | — | — |
phpdocumentor/reflection-docblock Version ^5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.