The source includes a README, tests, a matching repository, and an MIT license, which make the package understandable and legally usable. Its zero recent activity and lack of security policy leave maintenance and vulnerability response uncertain.
42%
Total Score
50
72
83
The package has had no release in about five years and none in the last 12 months, indicating a strong abandonment risk despite its history of 39 releases.
The repository has zero commits and zero active maintainers in the last three months, reinforcing the abandonment concern shown by the release history.
There has been no issue or pull request activity in the last month, and no pull requests were merged, consistent with an inactive project.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but this offers no external sign of adoption or review.
Composer build tooling is present, but no security scanning tools are configured, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
web-token/jwt-key-mgmt Version ^2.0 | — | — |
web-token/jwt-signature-algorithm-ecdsa Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.