The package is licensed, documented, and has a small runtime dependency surface. Workflow checks include two high-confidence hygiene risks, including an unpinned container image.
52%
Total Score
75
100
88
50
The latest release was about 5 years and 8 months ago, with no releases in the last 12 months. This is a substantial maintenance concern for a package handling authentication, despite its three-release history showing it was once developed.
There were no commits and no active maintainers in the last 3 months, consistent with repository activity having stopped in January 2023. This materially increases abandonment risk.
Composer build tooling is present, but no security scanning tools were detected. For a JWT validation package, that is a meaningful transparency and maintenance gap.
The repository has no security policy. That makes vulnerability reporting and coordinated maintenance less clear for a security-sensitive library.
All 11 action references are unpinned, and the audit found high-confidence bot-condition and unpinned-image issues. The pull_request_target workflow has no untrusted checkout or script-injection sink, so these are hygiene risks rather than a severe workflow threat.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version >=5.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.