Usable with caveats: the package is licensed, clearly backed by a matching repository, and has a long release history, but recent repository activity is absent and no security policy or scanning is provided. Verify that v8.6.1 is the intended release because the stability signal reports v7.14.0 as latest.
68%
Total Score
67
100
88
75
Only one registry account has publishing access. That is a limited publishing base, although the matching source repository provides some continuity evidence.
The repository recorded zero commits and zero active maintainers in the last 3 months. This is a meaningful maintenance concern, though the recent push and release history provide some compensating evidence.
Composer is used for the build, but no security scanning tools are detected. The missing scanning reduces transparency around automated security checks.
No SECURITY policy is present in the repository, leaving vulnerability reporting and response expectations undocumented.
The assessed release is marked stable and not prerelease, but the signal reports v7.14.0 as the latest version while the assessed version is v8.6.1, creating a material data-consistency concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^5.0 | — | — |
lcobucci/clock Version ^3.0 | — | — |
scheb/2fa-bundle Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.