It has a clear MIT license, a focused artifact, and organization backing. The repository is not archived and was pushed recently, but those positives do not restore this release's supported status.
18%
Total Score
75
60
50
Packagist marks the entire package abandoned and explicitly names web-token/jwt-experimental as its replacement. This is a direct indication that new projects should not depend on this package.
The package has 96 releases and is mature, but it has had no releases in the last 12 months; its latest release was over two years ago. That lack of registry maintenance reinforces the abandonment status.
The repository had no commits and no active maintainers in the past 3 months. Although it was pushed in May 2025, current development activity is absent.
The repository has no security policy. This is a modest transparency and vulnerability-reporting gap, though it is secondary to the package's explicit abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
web-token/jwt-experimental Version ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.