The MIT license, tests, and README make the package understandable to integrate. Low adoption and no security policy add support risk for a JWT component.
38%
Total Score
50
75
83
The package has had only two releases, both in October 2019, with no release in nearly seven years. This is strong evidence of abandonment for a security-sensitive authentication component.
There are two open issues but no new or closed issues and no pull-request activity in the last month, providing no evidence of active maintenance.
The repository has only 7 stars, 2 forks, and no watchers. Popularity is not decisive, but these low adoption figures provide little supporting evidence of ongoing community use.
The repository has no security policy. For a JWT authentication component, this weakens vulnerability-reporting transparency and leaves the long maintenance gap less reassuring.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyperf/di Version ~1.1.0 | — | — |
hyperf/cache Version ~1.1.0 | — | — |
hyperf/utils Version ~1.1.0 | — | — |
lcobucci/jwt Version ^3.2 | — | — |
nesbot/carbon Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.