The replacement project is active, tested, and documented, with recent commits and security scanning. Maintenance remains concentrated in two contributors, and the repository has no published security policy.
42%
Total Score
67
81
75
Packagist marks the package abandoned at package scope and points users to a replacement repository, making this release a poor choice for a new dependency despite the source project remaining active.
The repository is owned by an individual rather than an organization, so the concentrated contributor activity has less organizational backing to offset it.
The package has 23 releases since August 2022, but only one release in the last 12 months; the latest release on August 8, 2026 shows recent activity but a thin current cadence.
Two contributors are active, but the top contributor made 80% of the last three months' commits, leaving maintenance meaningfully concentrated in one person.
No SECURITY.md or other published security policy was found, reducing transparency for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^7.0 | — | — |
vlucas/phpdotenv Version ^5.3 | — | — |
phpseclib/phpseclib Version ^3.0.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.