It includes tests, release notes, a clear MIT license, and a repository that matches the package. The source has had no commits or issue activity for more than 10 years, making future maintenance and compatibility a serious concern.
38%
Total Score
25
79
75
The latest release was published in May 2015, with no releases in the last 12 months. That long gap is strong evidence of abandonment risk despite four historical releases.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package having been inactive for more than 10 years.
There were no new or closed issues or pull requests in the last month, and existing issues remain open. This adds to the evidence that the project is not being maintained.
The repository uses Composer build tooling, but it has no security scanning tools. This is a minor hygiene gap that matters less than the much older maintenance problem.
No security policy is present in the repository, leaving vulnerability reporting guidance unclear. This is a transparency gap, not evidence that the package is unsafe by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ~2.0 | — | — |
guzzlehttp/guzzle Version 5.* | — | — |
illuminate/support Version >=4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.