The project has seen no repository commits or registry releases for nearly four years, and the linked repository does not identify this package. A license, README, changelog, and clean install-script profile provide useful transparency, but the single-maintainer project has limited security and maintenance evidence.
40%
Total Score
33
100
50
83
The package has had no releases in the last 12 months, and its five releases were concentrated on one day in November 2022. This strongly suggests an inactive release stream.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with roughly four years of inactivity. This is a major abandonment concern.
The repository name does not match the package name and its README does not mention the package, so the link may not represent the package's actual source. That weakens provenance and transparency.
Only one registry maintainer is listed, leaving a thin publishing base. The repository is user-owned, so there is no organization backing shown to compensate for that concentration.
The registry namespace and repository owner are the same individual account, confirming ownership continuity but showing no organizational backing to reduce single-person abandonment risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.