Package Health

gesdinet/jwt-refresh-token-bundle

The MIT license, security policy, tests, and upgrade documentation make adoption and maintenance transparent. Concentrated development and unpinned workflow actions warrant monitoring, but do not outweigh the project's overall maturity.

Latest v3.0.0PackagistPackagist

76%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Repo bus factorcaution

All 137 recent commits came from one contributor, creating a genuine continuity risk despite the high activity level and user-owned repository backing.

Workflow auditcaution

All three workflows were analyzed with no audit findings, no untrusted checkouts, and no script injection. However, all 15 action references are unpinned, leaving workflow builds exposed to upstream action changes.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Marcos Gómez Vilches

Direct Dependencies

DependencyLast ReleaseScore
symfony/config
Version ^8.0.9
symfony/console
Version ^8.0
symfony/http-kernel
Version ^8.0
doctrine/persistence
Version ^3.1 || ^4.0
symfony/security-core
Version ^8.0

Weekly Downloads

Info

Last Published
1 month ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform