jsonwebtoken - dependency health snapshot - depmedic

jsonwebtoken v9.0.0

JSON Web Token implementation (symmetric and asymmetric)

C
77/100 depmedic health score
snapshot taken 2026-04-28T07:20:36.846Z

Score breakdown

Popularity80/100
Maintenance50/100
Quality92/100
Risk (penalty for deprecated)100/100

Snapshot

Weekly downloads
1.8M
Monthly downloads
43.8M
npm dependents
0
GitHub stars
16K
Open issues
104
License
MIT
TypeScript types
no
Maintainers (top 5)
jake.lacey, lbalmaceda, ziluvatar, jstrutz, woloski

Embed the badge

Drop one of these into your README. Updates whenever depmedic re-runs the snapshot.

depmedic health: 77/100 (C)

![depmedic health](https://depmedicdev-byte.github.io/health/badge/jsonwebtoken.svg)

Use depmedic locally on this package

# In your project that depends on jsonwebtoken:
npm install jsonwebtoken
npx depmedic                    # vulnerability triage on your install
npx depmedic --severity=high    # CI-friendly: exits 1 on high+critical

Want a deep audit of jsonwebtoken for vendor review?

The Vendor Dossier PDF goes deeper than this snapshot: full advisory list (resolved + open), maintainer drift, release cadence, transitive risk, license tree. $9 one-time per package.

Order Vendor Dossier ($9) More tools

Org-wide monitoring

Track every package across your repos. Get an email when any one slips below your minimum grade. $19/mo.

Org Dep Health Monitor ($19/mo)