JSON Web Token (JWT) for webman plugin
61%
Total Score
caution
Usable with caveats: recent releases help, but inactive development and a license mismatch weaken confidence.
The manifest declares MIT while the artifact license file is recognized as Apache-2.0, creating an unresolved licensing mismatch despite license files existing in both the artifact and repository.
The registry namespace and repository owner are different individual accounts, with no organization backing shown. The package-to-repository relationship is nevertheless supported by the matching name and README mention.
The repository recorded zero commits and zero active maintainers during the last three months. This weakens evidence of ongoing maintenance, although the recent release history partly compensates.
The repository has zero stars, forks, and watchers, providing no community adoption or external review signal. Popularity is supporting evidence, so this limits confidence more than it determines the verdict.
Composer build tooling is present, but no security-scanning tools were detected. That leaves security maintenance less transparent for a package handling authentication tokens.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^6.8 | — | — |
workerman/webman-framework Version ^1.2.1||^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.