The package includes a clear README, matching repository, and MIT licensing. Its young release history and absent recent commits leave maintenance capacity unproven; no security policy or scanning adds a smaller concern.
55%
Total Score
75
100
88
83
Only two releases exist over about six months, with the latest roughly four months ago. This is a young project with limited evidence of sustained maintenance.
There were zero commits and zero active maintainers during the last three months. For a package this young, that is a meaningful maintenance warning despite the repository not being archived.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence of immediate unfitness.
The repository has no security policy. For an authentication package handling tokens and signatures, the absence of documented vulnerability-reporting guidance is a real transparency concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^5.0|^6.0 | — | — |
guzzlehttp/guzzle Version ^6.3|^7.0 | — | — |
laravel/framework Version ^7.0|^8.0|^9.0|^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.