The repository has had no commits in the last three months, and all six workflow actions are unpinned. Licensing, tests, organization backing, a security policy, and read-only workflow permissions provide useful safeguards.
62%
Total Score
83
100
83
100
This is a 1.0.0 package with only one release, published about 3 years ago and with no releases in the last 12 months. That leaves limited evidence of release maturity and ongoing maintenance.
There were zero commits and zero active maintainers in the last three months. This weakens evidence of active maintenance, despite the recent repository push shown by repository_archived.
The repository has no stars and one fork, so external adoption evidence is limited. Popularity is supporting evidence rather than a health verdict, and organization backing partly offsets the small audience.
Composer build tooling is present, but no security scanning tools were detected. That is a hygiene gap rather than evidence of abandonment.
The single workflow was fully analyzed, uses read-only permissions, and has no detected dangerous triggers, untrusted checkouts, injection sinks, or audit findings. However, all six action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tymon/jwt-auth Version ^2.0 | — | — |
web-token/jwt-core Version ^3.2 | — | — |
web-token/jwt-key-mgmt Version ^3.2 | — | — |
web-token/jwt-signature Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.