Package Health

deadlymous/jwt

The package includes tests, a changelog, and no install-time scripts. Its sole registry maintainer, absent security policy, and conflicting license evidence provide little transparency around an otherwise inactive project.

Latest 1.0.3PackagistPackagist

28%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The latest release was about 5 years ago, with no releases in the last 12 months and only three releases overall. This is strong evidence of abandonment for a dependency that may need ongoing compatibility fixes.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers during the last 3 months, consistent with the package having been inactive since April 2021. No provided maintenance signal compensates for this gap.

Licensecaution

The artifact declares MIT, but the detected license text is Apache-2.0 despite license files being present. The mismatch creates a real licensing uncertainty even though the release is not unlicensed.

Repo package mentioncaution

The linked repository name does not match the package name, and its README does not mention the package. That weakens confidence that the repository is the package's genuine project home.

Security policycaution

The repository has no security policy. For an authentication and JWT package, this is a meaningful transparency gap because consumers have no documented vulnerability-reporting process.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

deadlymous

Direct Dependencies

DependencyLast ReleaseScore
lcobucci/jwt
Version ^3.3
phpdocumentor/reflection
Version ^4.0
phpdocumentor/reflection-docblock
Version ^5.2

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform