Package Health

naux/jwt-simple

The MIT license, matching repository, and lack of install-time scripts improve transparency. Maintenance has effectively stopped since December 2015, with little community backing and no security policy.

Latest 1.0.5PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The latest release was published in December 2015, and there have been no releases in about 10 years and 9 months. This is strong evidence of abandonment for a dependency receiving ongoing security fixes.

Repo commit activitydanger

There were no commits or active maintainers in the three months measured, consistent with the repository having been inactive since December 2015.

Project backingcaution

The repository is owned by an individual rather than an organization, providing limited visible project backing for a package with a single registry maintainer.

Repo popularitycaution

The repository has only 1 star, 1 fork, and 1 watcher. Low popularity is supporting evidence rather than a verdict, but it provides little evidence of community support alongside the inactivity.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured. For an old authentication-related library, that limits ongoing assurance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

NauxLiu

Direct Dependencies

DependencyLast ReleaseScore
namshi/jose
Version ^6.0
—
—

Weekly Downloads

Info

Last Published
10 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform