Package Health

evaneos/jwt

The organization-backed repository includes release notes, a matching README, and a stable major release. It lacks licensing and security-policy documentation, while recent maintenance and workflow pinning are weak.

Latest v1.0.0PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Licensecaution

Neither the package metadata nor the linked repository contains a declared or detected license file. That creates a material adoption and redistribution concern.

Release historycaution

The package has eight releases since January 2016, but none in the last three years; the latest release was in March 2023. This indicates a meaningful maintenance slowdown for a library dependency.

Repo commit activitycaution

The repository recorded no commits and no active maintainers in the last three months, consistent with the extended gap since the latest release. This raises abandonment risk despite the repository remaining available.

Security policycaution

The linked repository has no security policy. For a JWT library this reduces transparency around vulnerability reporting, although it does not by itself show that the code is unsafe.

Workflow auditcaution

The single workflow was fully analyzed with no high- or medium-severity findings, and it has no dangerous triggers or untrusted checkouts. However, all three action references are unpinned, leaving a modest build-integrity hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Charles Desneuf
Rémi San

Direct Dependencies

DependencyLast ReleaseScore
evaneos/security
Version ^0.1
—
—
firebase/php-jwt
Version ^6.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform