Tests and release notes improve transparency, but the missing license and security policy leave important gaps. The package is explicitly maintained only for internal use, limiting confidence for new dependencies.
32%
Total Score
50
50
50
No license declaration or license file was detected in the package or repository. This creates a material legal and adoption gap for a dependency.
The artifact includes a README, tests, and release notes for this version, which supports transparency. However, the README says Silex is end-of-life and that this package will be maintained only for internal use, materially limiting its suitability for new projects.
The package has had no release in nearly five years, despite seven releases over its lifetime and a stable final version. This indicates a serious abandonment risk for a dependency.
The repository recorded 0 commits and 0 active maintainers in the last three months, consistent with the package's stated internal-only maintenance status. No provided signal shows current maintenance capacity.
The repository has no security policy. That is a transparency and vulnerability-reporting gap, especially for a package providing JWT authentication functionality.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
evaneos/jwt Version ^0.5.0 | — | — |
pimple/pimple Version ^3.0 | — | — |
symfony/security Version ^2.7||^3.0||^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.