Package Health

ethanzway/laravel-jwt

The project offers limited transparency, with no license, security policy, or security scanning evidence. Its matching repository and stable, non-deprecated release provide some reassurance, but long-term support remains uncertain.

Latest v5.5.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

This package has only one release, published over four years ago, and no releases in the last 12 months. That is strong evidence of abandonment risk for a dependency, despite the release being stable.

Repo commit activitydanger

The repository recorded no commits and no active maintainers during the last three months. Combined with the one-release history, this indicates no observed ongoing maintenance.

Licensecaution

No license is declared, and no license file was detected in either the package or repository. This creates a genuine adoption and redistribution concern.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. This is a modest process gap rather than evidence of an unsafe release by itself.

Security policycaution

The repository has no security policy. For a package handling JWT authentication, this reduces transparency around vulnerability reporting and response.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
namshi/jose
Version ^7.0
—
—
lcobucci/jwt
Version ^3.2
—
—
nesbot/carbon
Version ^1.0
—
—
illuminate/auth
Version 5.*
—
—
illuminate/http
Version 5.*
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform