Usable with caveats: the package has a stable, actively released history, clear licensing, and matching organization-backed source repository. However, the repository shows no commits in the last three months and has no security policy or scanning, so maintenance and security transparency should be monitored.
70%
Total Score
75
100
89
90
The repository recorded zero commits and zero active maintainers during the last three months, a concrete sign of currently limited development activity. The recent release history and latest repository push partly compensate, but the maintenance signal remains a concern.
There are no open issues or pull requests, and no issue or pull-request activity in the last month. This is neutral for a small package but provides little evidence of an active user or maintainer community.
The repository has only 1 star and 1 fork, which limits outside validation and bus-factor support. Popularity is supporting evidence rather than a health verdict, and the release history provides stronger evidence of activity.
Composer is used for the build, but no security scanning tool is configured. The missing scanning reduces security-process transparency, though it is not evidence that the package is malicious.
The repository has no security policy, leaving vulnerability-reporting expectations and response guidance undocumented for an authentication-related package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^7.0 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
guzzlehttp/guzzle Version ^7.9 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.