The organization-backed repository includes release notes, a matching README, and a stable major release. It lacks licensing and security-policy documentation, while recent maintenance and workflow pinning are weak.
55%
Total Score
75
83
75
Neither the package metadata nor the linked repository contains a declared or detected license file. That creates a material adoption and redistribution concern.
The package has eight releases since January 2016, but none in the last three years; the latest release was in March 2023. This indicates a meaningful maintenance slowdown for a library dependency.
The repository recorded no commits and no active maintainers in the last three months, consistent with the extended gap since the latest release. This raises abandonment risk despite the repository remaining available.
The linked repository has no security policy. For a JWT library this reduces transparency around vulnerability reporting, although it does not by itself show that the code is unsafe.
The single workflow was fully analyzed with no high- or medium-severity findings, and it has no dangerous triggers or untrusted checkouts. However, all three action references are unpinned, leaving a modest build-integrity hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
evaneos/security Version ^0.1 | — | — |
firebase/php-jwt Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.