The repository shows recent, sustained work from five contributors, with tests, release notes, pinned actions, and security scanning. The SBOM workflow has high-confidence template-injection findings, and no security policy is published, so workflow hygiene deserves attention.
82%
Total Score
100
100
94
83
This is a young package, 85 days old with one release, so long-term release reliability is not yet established; recent repository activity partly compensates.
No repository security policy is published, leaving disclosure and response expectations unclear for a cryptographic library.
All five workflows were analyzed, use all 16 actions with none unpinned, and have no untrusted triggers or script-injection sinks. However, the SBOM workflow has six high-confidence template-injection findings; without a corroborating dangerous trigger this is a workflow hygiene concern rather than a severe health risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.