Package Health

web-token/jwt-framework

Healthy and suitable to depend on. It has frequent releases, active recent development, strong repository hygiene, and a maintained organization-owned project; the main caveat is that one contributor made 92% of recent commits.

Latest 4.2.3PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Repo bus factorcaution

Recent work is highly concentrated: one contributor made 44 of 48 commits, or about 92%, although four additional contributors were active and the repository is organization-owned.

Token permissionscaution

Five of seven workflows omit top-level token permissions, which is a transparency and least-privilege gap, though none declares top-level write access and two explicitly use read-only permissions.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Florent Morselli
All contributors

Direct Dependencies

DependencyLast ReleaseScore
psr/clock
Version ^1.0
—
—
brick/math
Version ^0.12|^0.13|^0.14|^0.15|^0.16|^0.17|^0.18|^0.19|^0.20|^1.0
—
—
symfony/config
Version ^7.0|^8.0
—
—
symfony/console
Version ^7.0|^8.0
—
—
symfony/http-kernel
Version ^7.0|^8.0
—
—

Weekly Downloads

Info

Last Published
16 days ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform