Clear licensing, useful documentation, and no install-time scripts make adoption straightforward. The main limitations are concentrated recent contributions and the absence of a published security policy or security-scanning tooling.
78%
Total Score
67
94
75
All recent commits came from one contributor, creating a meaningful continuity risk. Organization ownership provides some handoff capacity, but no second contributor was active in the measured period.
Four commits were made in the last three months, showing recent activity, but all were made by one active maintainer, limiting demonstrated maintenance depth.
Composer build tooling is present, but no security-scanning tooling was detected, leaving security hygiene less demonstrable.
The repository has no published security policy, reducing transparency about how vulnerability reports are handled for an authentication-focused bundle.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
psr/clock Version ^1.0 | — | — |
lcobucci/jwt Version ^5.0 | — | — |
psr/container Version ^1.1 || ^2.0 | — | — |
symfony/config Version ^5.4 || ^6.3 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.