TODO: app common
65%
Total Score
caution
Frequent releases and tests help, but the pre-1.0 package has incomplete documentation and a thin maintainer base.
A post-autoload-dump install-time script runs during installation, adding operational complexity and a supply-chain review point even though no dangerous behavior is shown here.
Only one registry account, named Dev, has publish access, creating a thin operational and continuity base despite the package's frequent releases.
The artifact includes a README and tests, but the README is only 729 characters and explicitly lists major TODOs, leaving consumer documentation incomplete.
The release is not a prerelease, but the package remains below 1.0 and is not on a stable major version, so its API may still change substantially.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^5.4 | — | — |
illuminate/contracts Version ^10.0||^11.0||^12.0 | — | — |
pusher/pusher-php-server Version ^7.2 | — | — |
php-open-source-saver/jwt-auth Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.