PHPackages                             sansec/magento2-module-cosmic-sting-jwt - PHPackages - PHPackages  [Skip to content](#main-content)[PHPackages](/)[Directory](/)[Categories](/categories)[Trending](/trending)[Leaderboard](/leaderboard)[Changelog](/changelog)[Analyze](/analyze)[Collections](/collections)[Log in](/login)[Sign up](/register)

1. [Directory](/)
2. /
3. [Authentication &amp; Authorization](/categories/authentication)
4. /
5. sansec/magento2-module-cosmic-sting-jwt

ActiveMagento2-module[Authentication &amp; Authorization](/categories/authentication)

sansec/magento2-module-cosmic-sting-jwt
=======================================

0.1.0(2y ago)1738.6k↓27.7%2MITPHP

Since Jul 15Pushed 2y ago4 watchersCompare

[ Source](https://github.com/sansecio/magento2-module-cosmic-sting-jwt)[ Packagist](https://packagist.org/packages/sansec/magento2-module-cosmic-sting-jwt)[ RSS](/packages/sansec-magento2-module-cosmic-sting-jwt/feed)WikiDiscussions main Synced 2w ago

READMEChangelogDependencies (1)Versions (2)Used By (0)

Important Notice
================

[](#important-notice)

Adobe has released a [hotfix for the isolated patch](https://experienceleague.adobe.com/en/docs/commerce-knowledge-base/kb/troubleshooting/known-issues-patches-attached/security-update-available-for-adobe-commerce-apsb24-40-revised-to-include-isolated-patch-for-cve-2024-34102?lang=en#hotfix) that ensures only the latest encryption key is used for JWTs. If you have applied this hotfix, this module is no longer necessary.

Cosmic Sting JWT
================

[](#cosmic-sting-jwt)

As [CosmicSting](https://sansec.io/research/cosmicsting-hitting-major-stores) enables attackers to read any file, attackers can steal Magento's secret encryption key. This encryption key can be used to generate JSON Web Tokens with full administrative API access.

Adobe offers a solution to change the encryption key, but all it does is *add* an additional key and then attempts to re-encrypt existing secrets with this key. It does nothing to invalidate the old key that is still being referenced in `app/etc/env.php`.

This module ensures that JWTs are only ever read using the latest encryption key. It is provided as-is and without any warranty or guarantees. Test extensively and use at own risk.

Installation
------------

[](#installation)

```
composer require sansec/magento2-module-cosmic-sting-jwt
bin/magento setup:upgrade

```

License
-------

[](#license)

[MIT License](./LICENSE) - Copyright (c) 2024 Sansec

###  Health Score

27

—

LowBetter than 46% of packages

Maintenance20

Infrequent updates — may be unmaintained

Popularity38

Limited adoption so far

Community10

Small or concentrated contributor base

Maturity31

Early-stage or recently created project

 Bus Factor1

Top contributor holds 100% of commits — single point of failure

How is this calculated?**Maintenance (25%)** — Last commit recency, latest release date, and issue-to-star ratio. Uses a 2-year decay window.

**Popularity (30%)** — Total and monthly downloads, GitHub stars, and forks. Logarithmic scaling prevents top-heavy scores.

**Community (15%)** — Contributors, dependents, forks, watchers, and maintainers. Measures real ecosystem engagement.

**Maturity (30%)** — Project age, version count, PHP version support, and release stability.

###  Release Activity

Cadence

Unknown

Total

1

Last Release

764d ago

### Community

Maintainers

![](https://avatars.githubusercontent.com/u/743661?v=4)[Daniel Sloof](/maintainers/danslo)[@danslo](https://github.com/danslo)

---

Top Contributors

[![danslo](https://avatars.githubusercontent.com/u/743661?v=4)](https://github.com/danslo "danslo (10 commits)")

### Embed Badge

![Health badge](/badges/sansec-magento2-module-cosmic-sting-jwt/health.svg)

```
[![Health](https://phpackages.com/badges/sansec-magento2-module-cosmic-sting-jwt/health.svg)](https://phpackages.com/packages/sansec-magento2-module-cosmic-sting-jwt)
```

###  Alternatives

[tg/tgwebvalid

An easy way to validate Telegram Login Widget and Telegram Mini App users on your website using PHP

6827.5k1](/packages/tg-tgwebvalid)[vitalybaev/laravel5-dkim

Laravel 5/6 package for signing outgoing messages with DKIM.

3163.1k](/packages/vitalybaev-laravel5-dkim)[kissdigital-com/apple-sign-in-client-secret-generator

PHP package for generating 'client secret' for Sign In with Apple

2125.5k](/packages/kissdigital-com-apple-sign-in-client-secret-generator)[denniseilander/laravel-passport-scopes-restriction

Restrict scopes for different Laravel Passport clients.

1636.3k](/packages/denniseilander-laravel-passport-scopes-restriction)

PHPackages © 2026

[Directory](/)[Categories](/categories)[Trending](/trending)[Changelog](/changelog)[Analyze](/analyze)
