Package Health

little-apps/littlejwt

The package includes tests, a changelog, a security policy, and a recent release. Maintenance is concentrated in one contributor, while the workflow audit found a high-confidence bot-condition issue and all seven action references are unpinned.

Latest v3.0.0PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Lifecycle scriptscaution

A post-autoload-dump install-time script is present. This adds execution surface during installation, but the signal alone does not show harmful or unexpected behavior.

Release historycaution

The project has released 18 times since February 2022 and published one release in the last 12 months, including this recent version; the low recent cadence warrants some caution.

Repo bus factorcaution

One contributor made all commits during the last 3 months, leaving maintenance dependent on a single active contributor.

Repo commit activitycaution

Only one commit was recorded in the last 3 months, indicating limited recent development activity even though the repository was recently updated.

Workflow auditcaution

The audit completed all three workflows and found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow. All seven action references are unpinned, and one workflow grants top-level write permissions, creating additional CI supply-chain hygiene concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Nick H

Direct Dependencies

DependencyLast ReleaseScore
illuminate/contracts
Version ^13.0 || ^12.0
web-token/jwt-library
Version ^4.1
spatie/laravel-package-tools
Version ^1.19

Weekly Downloads

Info

Last Published
3 months ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform