The package has clear consumer documentation, tests, and a changelog, with a stable nondeprecated release and no install-time scripts. Keep expectations modest for ongoing support.
64%
Total Score
75
83
83
The package is mature, with 32 releases over roughly 9.6 years, but it has had no releases in the last 12 months despite a median historical interval of about 14 days. This indicates a meaningful slowdown in publishing activity.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Combined with 0 releases in the last 12 months, this is a clear maintenance concern.
The repository has only 2 stars, 0 forks, and 1 watcher. Low adoption is supporting evidence of a small ecosystem and limited independent visibility, but it is not by itself an abandonment verdict.
The repository uses Composer build tooling but reports no security-scanning tools. This is a modest process gap, partially offset by the presence of tests and a structured source tree.
The repository has no security policy. For a JWT integration package, this reduces the transparency of vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.0|^3.0 | — | — |
lcobucci/jwt Version ^4.0|^5.0 | — | — |
lcobucci/clock Version ^3.0 | — | — |
codercat/jwk-to-pem Version ^1.1 | — | — |
symfony/http-client Version ^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.