Package Health

jekk0/jwt-auth

The repository includes tests, a changelog, and release notes, while the package is licensed and not deprecated or archived. Its workflow leaves all three actions unpinned and the repository has no security policy.

Latest 1.0.0PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Maintainerscaution

One registry maintainer publishes the package, and the repository is owned by that same individual. This is a thin maintainer base with limited visible continuity capacity.

Release historycaution

The package has had no release in the last 12 months, despite six releases overall, and its latest release was about 18 months ago. This is meaningful abandonment risk for a relatively young package.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers over the last three months, providing no evidence of ongoing maintenance. The existing tests and changelog provide some maturity evidence but do not offset the inactivity.

Security policycaution

The repository has no security policy. For an authentication package, this weakens vulnerability-reporting transparency and is a genuine maintenance concern.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all three action references are unpinned, leaving the build exposed to changing upstream action code.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

jekk0

Direct Dependencies

DependencyLast ReleaseScore
firebase/php-jwt
Version ^6.10
—
—
illuminate/console
Version ^10.0|^11.0|^12.0
—
—
illuminate/support
Version ^10.0|^11.0|^12.0
—
—
illuminate/database
Version ^10.0|^11.0|^12.0
—
—
illuminate/contracts
Version ^10.0|^11.0|^12.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform