Package Health

free-work-agsi/jwt-refresh-token-bundle

The package has a clear MIT license, useful documentation, and a substantial source tree with specification files. Organization ownership partly offsets the single registry maintainer, but there is no security policy or security scanning.

Latest v0.9.6PackagistPackagist

36%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

The latest release was published in May 2022, with no releases in the following four years and no releases in the last 12 months. That is strong evidence of abandonment for a dependency.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving little evidence of ongoing maintenance.

Repo issue activitycaution

There were no new or merged pull requests and no issue activity in the last month. This reinforces the absence of recent project activity, although issue volume alone is not decisive.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. This weakens evidence that dependency or code risks are monitored.

Security policycaution

The repository has no security policy, which is a transparency gap for a package handling JWT refresh tokens and authentication-related functionality.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Marcos Gómez Vilches

Direct Dependencies

DependencyLast ReleaseScore
symfony/validator
Version ~3.4|~4.0|~5.0
symfony/framework-bundle
Version ~3.4|~4.0|~5.0
lexik/jwt-authentication-bundle
Version ^1.1|^2.0@dev

Weekly Downloads

Info

Last Published
4 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform