Laravel/Symfony JWT authorization service
38%
Total Score
unhealthy
Risky: no release or commit activity since July 2020, with no security scanning to offset the abandonment risk.
The package has made no release in more than six years, and all five releases were published within one day in July 2020. This strongly suggests the project is no longer maintained, although the stable 1.0.5 version reduces version-churn risk.
The repository has recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but that does not compensate for the absence of recent work.
The repository has zero stars and forks and only one watcher, providing little evidence of a broader user or contributor base. Popularity is supporting evidence rather than a verdict, so this reinforces—but does not independently establish—the maintenance concern.
Composer is used for builds, but no security-scanning tooling is present. For an authentication package, that is a meaningful transparency and maintenance gap.
The repository has no security policy, leaving no documented process for reporting vulnerabilities in a security-sensitive JWT authorization package. Its MIT license and README provide basic transparency but do not replace a response policy.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-foundation Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.