Package Health

spomky-labs/jose

The release is stable, licensed, tested in the source repository, and documented with release notes. Security scanning and a security policy are absent, adding avoidable maintenance risk.

Latest v7.1.0PackagistPackagist

12%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

56

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned and recommends web-token/jwt-framework, directly indicating that this release should not be adopted for new dependencies.

Release historydanger

The package has 80 historical releases but none in the last 12 months, and its latest release was over eight years ago. Earlier release frequency does not compensate for the prolonged stop.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, confirming that current maintenance has collapsed rather than merely slowed.

Repository archiveddanger

The linked repository is archived, with its last push over six years ago; this is strong evidence that upstream maintenance has ended.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. That weakens ongoing assurance, although the archived state is the more consequential concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Florent Morselli
All contributors

Direct Dependencies

DependencyLast ReleaseScore
psr/cache
Version ^1.0
—
—
mdanter/ecc
Version 0.5.*
—
—
beberlei/assert
Version ^2.4
—
—
fgrosse/phpasn1
Version ^2.0
—
—
spomky-labs/base64url
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
8 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform