browserify version of publicEncrypt & privateDecrypt
58%
Total Score
50
79
100
50
No build attestation or trusted-publisher provenance is available for the release, so consumers have less evidence connecting the published artifact to its source. This lowers supply-chain transparency but is not by itself evidence that the package is unsafe.
The latest release was published nearly eight years ago, and there were no releases in the last 12 months. This is a meaningful freshness and maintenance concern, despite the package having 11 releases and a stable release history earlier in its life.
The repository recorded 0 commits and 0 active maintainers in the last three months. Although the repository was pushed more recently than the package release, current development activity is not evident.
The repository name does not match the package name and its README does not mention the package. That makes the source relationship less transparent, even though the naming difference could reflect a related project layout.
No type declarations are provided, which makes integration less convenient for typed consumers. This is a consumer-ergonomics gap rather than a severe maintenance risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bn.js Version ^4.1.0 | — | — |
parse-asn1 Version ^5.0.0 | — | — |
create-hash Version ^1.1.0 | — | — |
randombytes Version ^2.0.1 | — | — |
safe-buffer Version ^5.1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.