Package Health

lcobucci/jwt

Healthy and suitable to depend on. It has a long release history, a stable current version, active repository maintenance, tests, release notes, and strong project transparency; the main caveats are limited recent contributor activity and missing explicit workflow token permissions.

Latest 5.6.0PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Are you affected? Scan for Free

Health Score Breakdown

Package scaffoldingcaution

The published artifact lacks a README, which is a minor consumer-facing documentation gap for a library. This is partly compensated by repository documentation, repository tests, and release notes for this exact version.

Repo bus factorcaution

Recent work is concentrated in two contributors, with the top contributor making about 71% of commits. The second active contributor provides some continuity, but the individual-owner project still has a relatively thin recent contributor base.

Repo toolingcaution

The repository uses Composer and Make-based build tooling, but no security-scanning tool was detected. This is a transparency and defense-in-depth gap, not evidence of unsafe behavior by itself.

Token permissionscaution

None of the eight workflows declares top-level token permissions. Although no workflow has an explicit top-level write permission or a detected dangerous pattern, the lack of least-privilege declarations is a workflow hygiene concern.

Vulnerabilities

TitleVersionsSeverity
CVE-2021-41106
lcobucci/jwt is vulnerable to Insufficient Verification of Data Authenticity in versions 3.4.0 - 3.4.6, 4.0.0 - 4.0.4 and 4.1.0 - 4.1.5.
3.4.0 - 3.4.64.0.0 - 4.0.44.1.0 - 4.1.5
Medium

Package versions

Maintainers

Luís Cobucci

Direct Dependencies

DependencyLast ReleaseScore
psr/clock
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
11 months ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform