Healthy and suitable to depend on. It has a long release history, a stable current version, active repository maintenance, tests, release notes, and strong project transparency; the main caveats are limited recent contributor activity and missing explicit workflow token permissions.
86%
Total Score
88
100
89
90
The published artifact lacks a README, which is a minor consumer-facing documentation gap for a library. This is partly compensated by repository documentation, repository tests, and release notes for this exact version.
Recent work is concentrated in two contributors, with the top contributor making about 71% of commits. The second active contributor provides some continuity, but the individual-owner project still has a relatively thin recent contributor base.
The repository uses Composer and Make-based build tooling, but no security-scanning tool was detected. This is a transparency and defense-in-depth gap, not evidence of unsafe behavior by itself.
None of the eight workflows declares top-level token permissions. Although no workflow has an explicit top-level write permission or a detected dangerous pattern, the lack of least-privilege declarations is a workflow hygiene concern.
| Title | Versions | Severity |
|---|---|---|
CVE-2021-41106 lcobucci/jwt is vulnerable to Insufficient Verification of Data Authenticity in versions 3.4.0 - 3.4.6, 4.0.0 - 4.0.4 and 4.1.0 - 4.1.5. | 3.4.0 - 3.4.64.0.0 - 4.0.44.1.0 - 4.1.5 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.