Token-based subscription auth for Resonate: skip /broadcasting/auth for mobile and S2S clients with a JWT
68%
Total Score
caution
Usable with caveats: one-person maintenance and two unpinned workflow actions limit confidence.
Only one registry account can publish releases. That is a real continuity concern for a young package, although repository activity shows the same maintainer is currently active.
The repository is owned by the same individual namespace as the package, so there is no organization backing to offset the concentrated maintenance base.
One contributor made all eight recent commits, creating a high handoff and abandonment risk for ongoing maintenance.
Eight commits in the last three months, all by one active maintainer, show current work but limited maintenance depth.
The repository has no stars, forks, or watchers. This is weak supporting evidence for maturity, but popularity alone does not outweigh the demonstrated recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^7.0 | — | — |
illuminate/support Version ^13.0 | — | — |
webpatser/resonate Version ^0.7 | — | — |
illuminate/contracts Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.