The project offers limited transparency, with no license, security policy, or security scanning evidence. Its matching repository and stable, non-deprecated release provide some reassurance, but long-term support remains uncertain.
38%
Total Score
0
75
50
This package has only one release, published over four years ago, and no releases in the last 12 months. That is strong evidence of abandonment risk for a dependency, despite the release being stable.
The repository recorded no commits and no active maintainers during the last three months. Combined with the one-release history, this indicates no observed ongoing maintenance.
No license is declared, and no license file was detected in either the package or repository. This creates a genuine adoption and redistribution concern.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest process gap rather than evidence of an unsafe release by itself.
The repository has no security policy. For a package handling JWT authentication, this reduces transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
namshi/jose Version ^7.0 | — | — |
lcobucci/jwt Version ^3.2 | — | — |
nesbot/carbon Version ^1.0 | — | — |
illuminate/auth Version 5.* | — | — |
illuminate/http Version 5.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.