There is no license, README, or security policy to help consumers evaluate and adopt the code. The single maintainer and empty activity record leave little evidence of current support.
32%
Total Score
0
42
50
The package has only one release, published over 8 years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a dependency intended for ongoing use.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, while its last push was in July 2018. This indicates no visible current maintenance.
No license is declared, and neither the artifact nor the repository contains a license file. This creates a real adoption and redistribution risk.
The package has no README, which is a meaningful documentation gap for a library consumers must integrate; absent tests and changelog files are normal packaging practice and do not count against it.
The repository name does not match the package name, and the README contains no confirmed package mention. That leaves some uncertainty that the linked repository is the intended source.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^3.2 | — | — |
tymon/jwt-auth Version ^1.0.0-rc.1 | — | — |
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.