Package Health

medzuch/jwt-php

The repository has a clear README, security policy, tests, changelog, and release notes, with active work continuing recently. Its short history, highly concentrated commits, absent security-scanning tooling, and entirely unpinned workflow actions leave some maintenance and build-integrity risk.

Latest v1.2.1PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Release historycaution

The project is only 45 days old, despite having eight releases; this shows active early development but provides limited evidence of long-term maintenance.

Repo bus factorcaution

Two contributors are active, but one accounts for 17 of 18 recent commits, leaving maintenance heavily dependent on a single person.

Repo toolingcaution

Composer and Make are used for builds, but no security-scanning tools were detected, leaving a modest verification gap for a security-sensitive library.

Workflow auditcaution

Both workflows were fully audited with no high-confidence findings or untrusted checkouts, but all 13 action references are unpinned and one workflow grants top-level write permissions. These are workflow-hygiene concerns without an observed untrusted sink.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Marcin Mech

Direct Dependencies

DependencyLast ReleaseScore
psr/clock
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
4 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform