Healthy and suitable to depend on. It has regular recent releases, active repository work, strong tests and release notes, and no deprecation or archival concerns; maintenance is concentrated in one recent contributor and the repository lacks a security policy.
84%
Total Score
75
100
100
80
All 14 recent commits came from one contributor, creating a real continuity concern; organization ownership provides some handoff capacity, but no second recent contributor is shown.
There were 14 commits in the last three months, but all came from one active maintainer, so current work is strong while continuity depends heavily on that contributor.
No security policy was found, leaving vulnerability-reporting guidance unclear for a security-sensitive authentication library.
Five workflows lack top-level permission declarations and one release workflow requests top-level write access, which is broader than ideal even though no dangerous workflow pattern was detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^2.0 || ^3.0 | — | — |
psr/http-client Version ^1.0 | — | — |
firebase/php-jwt Version ^7.0 | — | — |
league/oauth2-client Version ^2.8.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.