Clear documentation, tests, and release notes make integration straightforward. The short history, one-contributor recent activity, and absent security controls leave meaningful maturity and maintenance uncertainty.
70%
Total Score
75
100
88
83
The package is only 154 days old with two releases and a median interval of about 58 days, so its long-term maintenance pattern is not yet established.
All recent commits came from one contributor, creating concentration risk; organization ownership provides some handoff capacity but no second active contributor is shown.
Only one commit was recorded in the last three months from one active maintainer, which is thin evidence of ongoing development for a package this new.
Composer build tooling is present, but no security-scanning tool was detected, leaving a security-process gap for a library that handles JWT signing and verification.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.