Package Health

syastrebov/jwks-decoder

The repository includes tests and Psalm scanning, and its MIT declaration is clear. GitHub Actions use broad write permissions and unpinned actions, while no security policy is published.

Latest v0.1PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

This is a young package with only one release, published about 177 days ago, so there is little release history to demonstrate sustained maintenance.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, which leaves ongoing maintenance uncertain despite the repository being active enough to be fetched.

Security policycaution

No security policy is published, reducing transparency for reporting vulnerabilities in a package that handles JWKS and authentication-related data.

Workflow auditcaution

The single workflow gives every job a top-level write-capable token and both referenced actions are unpinned. No untrusted trigger, checkout, script injection, or auditor finding was reported, limiting this to workflow hygiene risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

syastrebov

Direct Dependencies

DependencyLast ReleaseScore
firebase/php-jwt
Version ^7.0
—
—

Weekly Downloads

Info

Last Published
6 months ago
Created
6 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform