Usable with caveats: the package has a stable release line, regular registry releases, a coherent source repository, and repository tests. However, repository development is currently inactive, the project has no security policy, and it has no observable community adoption, so review it before making it a core dependency.
63%
Total Score
50
100
89
88
The repository is owned by an individual account rather than an organization, so the project has limited visible institutional backing. This is a supporting concern, not evidence of abandonment by itself.
The repository recorded zero commits and zero active maintainers in the last 3 months. The recent release history partly compensates for this, but the lack of current source activity is a real maintenance concern.
The repository has zero stars, forks, and watchers, so there is no observable community adoption or external visibility to compensate for its small project footprint.
Composer is used as a build tool, but no security scanning tools are detected. For an OAuth and JWT integration package, the absence of automated security scanning modestly reduces transparency.
The repository has no security policy, leaving no documented process for reporting vulnerabilities in an authentication-related package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^4.1.5 || ^5.0.0 | — | — |
hyperf/guzzle Version ^3.1 | — | — |
hyperf/session Version ^3.1 | — | — |
lcobucci/clock Version ^2.0 || ^3.0 | — | — |
hyperf/contract Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.