Organization backing, stable versioning, and a clear MIT license provide useful context. The source repository is small and has had no commits in the last three months, so ongoing support is uncertain.
22%
Total Score
75
67
100
Packagist marks the entire package as abandoned and names web-token/jwt-library as its replacement. This is a severe adoption risk even though the specific release is stable.
The package has 96 releases since August 2018, but none in the last 12 months and its latest release was in February 2024. The long release gap supports the abandonment concern.
The repository recorded zero commits and zero active maintainers in the last three months. This weakens confidence in ongoing maintenance, despite a push recorded in May 2025.
The repository uses Composer, but no security-scanning tools were detected. That is a transparency and maintenance gap for a cryptographic package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
web-token/jwt-library Version ^3.3 | — | — |
spomky-labs/aes-key-wrap Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.