Package Health

evaneos/silex-jwt-provider

Tests and release notes improve transparency, but the missing license and security policy leave important gaps. The package is explicitly maintained only for internal use, limiting confidence for new dependencies.

Latest v3.1.0PackagistPackagist

32%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Licensecaution

No license declaration or license file was detected in the package or repository. This creates a material legal and adoption gap for a dependency.

Package scaffoldingcaution

The artifact includes a README, tests, and release notes for this version, which supports transparency. However, the README says Silex is end-of-life and that this package will be maintained only for internal use, materially limiting its suitability for new projects.

Release historycaution

The package has had no release in nearly five years, despite seven releases over its lifetime and a stable final version. This indicates a serious abandonment risk for a dependency.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last three months, consistent with the package's stated internal-only maintenance status. No provided signal shows current maintenance capacity.

Security policycaution

The repository has no security policy. That is a transparency and vulnerability-reporting gap, especially for a package providing JWT authentication functionality.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Charles Desneuf
Rémi San
Alexandre Dupuy

Direct Dependencies

DependencyLast ReleaseScore
evaneos/jwt
Version ^0.5.0
—
—
pimple/pimple
Version ^3.0
—
—
symfony/security
Version ^2.7||^3.0||^4.0
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform