The repository includes tests and Psalm scanning, and its MIT declaration is clear. GitHub Actions use broad write permissions and unpinned actions, while no security policy is published.
58%
Total Score
50
93
50
This is a young package with only one release, published about 177 days ago, so there is little release history to demonstrate sustained maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, which leaves ongoing maintenance uncertain despite the repository being active enough to be fetched.
No security policy is published, reducing transparency for reporting vulnerabilities in a package that handles JWKS and authentication-related data.
The single workflow gives every job a top-level write-capable token and both referenced actions are unpinned. No untrusted trigger, checkout, script injection, or auditor finding was reported, limiting this to workflow hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.