The package has a clear license, focused dependency set, and recent releases. Security documentation and automated scanning are absent, while maintenance is concentrated in two contributors; keep these limits in mind for a core API dependency.
78%
Total Score
83
100
94
50
The package runs a post-autoload-dump install-time script. This adds execution surface during Composer installation, though the signal does not show a dangerous script or otherwise establish a severe risk.
Two contributors are active, which provides some continuity, although the leading contributor made about 78% of recent commits and maintenance remains concentrated.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanning reduces assurance for a package handling authentication infrastructure.
The repository has no security policy, leaving reporting and disclosure expectations undocumented for an API package that includes JWT authentication.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^7.0 | — | — |
evolution-cms/evolution Version ^3.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.