The package includes a license, tests, a usable README, and no install-time scripts. Its maintenance appears dormant, with no recent commits and no releases in nearly three years; missing security scanning and unpinned workflow actions add adoption risk.
48%
Total Score
0
78
67
Only three releases exist, with none in the last 12 months; the latest release was about three years ago, indicating a possibly abandoned package.
There were no commits and no active maintainers in the last three months, reinforcing the long gap since the last release and raising abandonment risk.
The repository has one star and no forks, offering little external evidence of adoption or community support; this is supporting evidence rather than a verdict by itself.
Composer build tooling is present, but no security scanning tools were detected, leaving a transparency and maintenance gap for a JWT-related package.
The repository has no security policy, making it less clear how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.7 | — | — |
firebase/php-jwt Version ^6.4 | — | — |
psr/http-message Version ^1.0 | — | — |
guzzlehttp/guzzle Version ^7.5 | — | — |
phpro/api-problem Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.