using json web token for recaptcha, without session, without database
58%
Total Score
50
83
67
Only one registry publishing maintainer is listed, leaving a thin operational base if that person becomes unavailable; the repository is user-owned rather than organization-backed.
The package has four releases since April 2020, but no release in about 19 months, which raises a maintenance and abandonment concern for a dependency.
There were no commits and no active maintainers during the last three months; combined with the long time since the latest release, this is the strongest abandonment concern.
The repository has one star, no forks, and one watcher, indicating very limited external adoption and review. Low popularity is supporting evidence rather than a decisive defect.
Composer is used for builds, but no security scanning tools are present, leaving a modest transparency and maintenance gap for a security-related package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.