Risky to depend on: this package has had only one release, published over six years ago, with no recent repository activity. It is licensed and not deprecated or archived, but maintenance and security coverage are too thin for a dependable dependency.
43%
Total Score
25
100
78
83
The package has only one release, 1.1.0, first and last published on February 7, 2020, with no releases in the last 12 months. This strongly suggests abandonment and outweighs the otherwise stable version designation.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the absence of registry releases since 2020, this is strong evidence that maintenance has stopped.
The repository is owned by an individual user rather than an organization. This is not inherently unhealthy, but it indicates a thin ownership structure and provides less evidence of durable project backing.
The repository has only 2 stars, 0 forks, and 1 watcher. Low popularity alone is not disqualifying, but it provides little supporting evidence of broad review or community resilience for an already inactive project.
The repository uses Composer but has no security-scanning tools. Composer tooling is appropriate for the package, while the lack of automated security scanning is a maintenance and transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^5.0 | — | — |
swiftmailer/swiftmailer Version @stable | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.