The MIT license, matching repository, and lack of install-time scripts improve transparency. Maintenance has effectively stopped since December 2015, with little community backing and no security policy.
42%
Total Score
25
72
75
The latest release was published in December 2015, and there have been no releases in about 10 years and 9 months. This is strong evidence of abandonment for a dependency receiving ongoing security fixes.
There were no commits or active maintainers in the three months measured, consistent with the repository having been inactive since December 2015.
The repository is owned by an individual rather than an organization, providing limited visible project backing for a package with a single registry maintainer.
The repository has only 1 star, 1 fork, and 1 watcher. Low popularity is supporting evidence rather than a verdict, but it provides little evidence of community support alongside the inactivity.
Composer build tooling is present, but no security scanning tools are configured. For an old authentication-related library, that limits ongoing assurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
namshi/jose Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.