Package Health

healthrecoverysolutions/knox-token

This release is usable and reasonably transparent: it has an MIT license, a matching repository with tests and a small but complete package tree, organization backing, stable versioning, and no deprecation or install-time scripts. The main concerns are its very sparse release history, no commits in the last 3 months, zero public popularity metrics, and incomplete repository security hygiene such as no security policy, no security scanning, and unspecified workflow token permissions. These issues make it a caution-level dependency rather than an outright liability, especially for a security-sensitive token-signing library.

Latest 1.0.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Release historycaution

The package is 1121 days old but has only 2 releases, with 1 release in the last 12 months and a median release interval of about 1110 days; this indicates a slow release cadence and limited evidence of sustained evolution.

Repo commit activitycaution

There were 0 commits and 0 active maintainers in the last 3 months, which weakens evidence of ongoing maintenance; the recent repository push and one merged pull request provide only partial compensation.

Repo popularitycaution

The repository has 0 stars, 0 forks, and 0 watchers, providing no external adoption evidence; this is supporting caution rather than a verdict because the package is small and organization-backed.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tooling was detected; for a library that signs access tokens, the missing automated security coverage is a meaningful hygiene gap.

Security policycaution

No repository security policy was found. This reduces transparency around vulnerability reporting and response for a security-sensitive library.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Arkadiusz Kondas

Direct Dependencies

DependencyLast ReleaseScore
ramsey/uuid
Version ^3.8 || ^4.0
firebase/php-jwt
Version ^5.0 || ^6.0 || ^7.0

Weekly Downloads

Info

Last Published
24 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform