The release is stable, documented, licensed, and has a small dependency set. Those positives do not offset package deprecation, an archived repository, and minimal single-contributor activity.
18%
Total Score
67
100
64
100
Packagist marks the entire package as abandoned, with no replacement named. This is a direct warning against taking a new dependency on it.
The linked source repository is archived, which strongly indicates the project is no longer intended for active maintenance. A recent recorded push does not compensate for the repository's archived status.
The package has seven releases since October 2017, but its latest registry release was in November 2022 and it had no releases in the last 12 months. This supports an abandonment concern.
All recent repository commits came from one contributor, giving the project a complete short-term contributor concentration. Organization backing provides some handoff capacity, but the archived status remains decisive.
Only one commit was recorded in the last three months, from one active maintainer. That is limited maintenance evidence for an archived package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ~6.0 | — | — |
league/oauth2-client Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.