Its stable API, tests, license, and matching source repository support adoption. However, the last release was over 11 years ago, repository commits have stopped, and no security policy or scanning is present.
58%
Total Score
0
100
81
75
The package has only three releases, with no release in the last 12 months and the latest published over 11 years ago. This is a substantial maintenance concern despite the repository remaining available.
There were no commits and no active maintainers in the three months measured. Combined with the old registry release, this indicates the project is effectively inactive.
Composer is used for builds, but no security scanning tooling is present. The missing scanning is a modest transparency and maintenance gap rather than evidence of a failing build.
The repository has no security policy, which is a meaningful gap for a library handling XML encryption and signatures because it gives consumers no documented vulnerability-reporting path.
No GitHub Actions workflows were found, so there are no workflow hazards to report. This also means the audit provides no evidence of automated repository checks.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.