The package is clearly licensed, has a focused artifact, and avoids install-time scripts. Its small one-person project has no tests or security policy, so future maintenance and review capacity are limited.
52%
Total Score
50
79
83
The artifact includes a README, while the absence of tests and a changelog is normal packaging practice and is not treated as a gap. The source repository also has neither tests nor a changelog, limiting project transparency somewhat.
All 7 releases arrived during a very short initial burst, and there have been no releases in roughly 23 months. That suggests the package may be stable, but provides little evidence of ongoing maintenance.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long gap since the last release. This materially increases abandonment risk.
The repository has 0 stars and 0 forks, with 1 watcher. Popularity is only supporting evidence, but these numbers provide no additional community backing.
The linked repository has no security policy. For a package handling Ed25519 JWT authentication, that is a meaningful transparency and vulnerability-reporting gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^4.0 | — | — |
tymon/jwt-auth Version ^2.0 | — | — |
illuminate/console Version ^9.0||^10.0||^11.0 | — | — |
illuminate/support Version ^9.0||^10.0||^11.0 | — | — |
illuminate/filesystem Version ^9.0||^10.0||^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.