The package is clearly documented, licensed, and tied to an organization-owned repository with matching names. Its single-release history provides little evidence of long-term maintenance yet, so pinning this exact version is prudent.
72%
Total Score
75
100
88
88
This release is the package's first and only release, published less than one day ago, so there is no demonstrated release continuity or maintenance history yet. That is an evidence gap rather than proof of abandonment.
There were no commits and no active maintainers in the last three months, but the repository itself was created or updated less than one day ago and the package has only just released. This limits evidence of sustained maintenance without establishing abandonment.
The repository uses Composer build tooling, appropriate for this package, but no security-scanning tool was detected. For this very small metapackage the omission is a modest hygiene gap, not a severe risk.
The repository has no security policy. That reduces transparency for reporting vulnerabilities, although the package is a small type-definition metapackage rather than an application handling credentials.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/firebase-php-jwt-impl Version ~7.1.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.