Package Health

yuanyuanli/jwt

JSON Web Token (JWT) for webman plugin

Latest v1.2.6PackagistPackagist

61%

Total Score

caution

Usable with caveats: recent releases help, but inactive development and a license mismatch weaken confidence.

Health Score Breakdown

Licensecaution

The manifest declares MIT while the artifact license file is recognized as Apache-2.0, creating an unresolved licensing mismatch despite license files existing in both the artifact and repository.

Project backingcaution

The registry namespace and repository owner are different individual accounts, with no organization backing shown. The package-to-repository relationship is nevertheless supported by the matching name and README mention.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers during the last three months. This weakens evidence of ongoing maintenance, although the recent release history partly compensates.

Repo popularitycaution

The repository has zero stars, forks, and watchers, providing no community adoption or external review signal. Popularity is supporting evidence, so this limits confidence more than it determines the verdict.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. That leaves security maintenance less transparent for a package handling authentication tokens.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
firebase/php-jwt
Version ^6.8
—
—
workerman/webman-framework
Version ^1.2.1||^2.0
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform