Package Health

afk11/pkcs5

The package has a usable layout, tests, an MIT license, and no install-time scripts. Its limited security practices and very small project footprint make long-term reliance difficult.

Latest v0.0.10PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The ten releases were clustered within hours in July 2016, with no releases in about 10 years. This is strong evidence of abandonment for a library that consumers may need to maintain over time.

Repo commit activitydanger

The repository has had no commits and no active maintainers in the past three months, and its last push was in July 2016. The long-standing lack of activity materially raises maintenance risk.

Package scaffoldingcaution

The package includes a README and tests, but the README explicitly says the library is incomplete and not fully tested. Tests provide some support, while that warning is a significant concern for cryptographic code.

Repo popularitycaution

The repository has one star, no forks, and one watcher, providing little evidence of external review or adoption. Popularity is supporting evidence only, but this reinforces the maintenance concerns.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. That is a modest transparency and maintenance gap for a cryptographic package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
fgrosse/phpasn1
Version 1.5.1
—
—
paragonie/random_compat
Version 2.0.*
—
—

Weekly Downloads

Info

Last Published
10 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform