The package has a usable layout, tests, an MIT license, and no install-time scripts. Its limited security practices and very small project footprint make long-term reliance difficult.
38%
Total Score
0
50
50
The ten releases were clustered within hours in July 2016, with no releases in about 10 years. This is strong evidence of abandonment for a library that consumers may need to maintain over time.
The repository has had no commits and no active maintainers in the past three months, and its last push was in July 2016. The long-standing lack of activity materially raises maintenance risk.
The package includes a README and tests, but the README explicitly says the library is incomplete and not fully tested. Tests provide some support, while that warning is a significant concern for cryptographic code.
The repository has one star, no forks, and one watcher, providing little evidence of external review or adoption. Popularity is supporting evidence only, but this reinforces the maintenance concerns.
Composer build tooling is present, but no security-scanning tools were detected. That is a modest transparency and maintenance gap for a cryptographic package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
fgrosse/phpasn1 Version 1.5.1 | — | — |
paragonie/random_compat Version 2.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.