Package Health

sherinbloemendaal/yii2-jwt

JWT Authentication for Yii2

Latest 1.0.1PackagistPackagist

58%

Total Score

caution

Usable with caveats: no releases or commits for about 15 months, with one maintainer and weak workflow pinning.

Health Score Breakdown

Maintainerscaution

One registry maintainer is consistent with the repository being owned by an individual, but it leaves little visible publishing redundancy if that person becomes unavailable.

Release historycaution

Only two releases were published, and none appeared in the last 12 months; the latest release was about 15 months ago. This indicates a real maintenance concern despite the initially short five-day release interval.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months, consistent with the long gap since the latest release. This raises abandonment risk for a security-sensitive authentication library.

Security policycaution

No repository security policy was found. For a JWT authentication package, this is a transparency gap because users lack a documented channel and process for reporting vulnerabilities.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all five action references are unpinned, leaving the workflow exposed to upstream action changes.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sherin Bloemendaal

Direct Dependencies

DependencyLast ReleaseScore
lcobucci/jwt
Version ^5.0
—
—
yiisoft/yii2
Version ^2.0.52
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform