The package is small and focused, with a clear README, tests, a license, and only two runtime dependencies. Its sparse release history and no commits in the last three months make long-term maintenance less certain.
65%
Total Score
50
100
86
50
Only 2 releases have been published since October 2017, with a median interval of about 8.2 years; the latest release was about 9 months ago. This suggests limited release and maintenance momentum despite the recent release.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, which weakens evidence of ongoing maintenance.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a security-sensitive JWT library.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all 3 action references are unpinned. That leaves avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.