Risky to adopt: this release has had no update since February 2021, and the repository shows no recent commits or active maintainers. It has solid packaging, tests, licensing, and release notes, but the long inactivity makes ongoing compatibility and maintenance uncertain.
35%
Total Score
0
50
67
67
The package has only one release, published about 5 years and 7 months ago, with no releases in the last 12 months. That strongly suggests the package is abandoned or no longer maintained.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, matching the stale release history rather than providing evidence of ongoing maintenance.
Seven runtime dependencies are declared for an authentication library, including HTTP, JWT, cache, and JSON components. This is a meaningful dependency surface but not excessive for the package's stated role.
The repository has 0 stars and 0 forks, with only 2 watchers. Popularity is not decisive, but these numbers provide little supporting evidence of broad community use or review.
Composer build tooling is present, but no security scanning tools were detected. That is a transparency and maintenance gap, though it is less significant than the repository's long inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^1.0 | — | — |
guzzlehttp/psr7 Version ^1.2 | — | — |
firebase/php-jwt Version ~2.0|~3.0|~4.0|~5.0 | — | — |
psr/http-message Version ^1.0 | — | — |
guzzlehttp/guzzle Version ^5.3.1|^6.2.1|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.