PSR-7 stream decorators for WhatsApp-style encryption and decryption
58%
Total Score
caution
Only two releases and no commits in the last three months leave maintenance maturity uncertain despite tests and clear package structure.
The repository is owned by an individual user rather than an organization, so the single registry maintainer reflects a genuinely thin project base rather than normal organizational publishing hygiene.
The package has only two releases, both within a few minutes on February 9, 2026, and no later release across roughly eight months. This suggests limited release maturity, though the project is still relatively young.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the short release history, this is a meaningful maintenance concern.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these values provide no external adoption signal to offset the limited activity.
Composer is used as a build tool, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.0 | — | — |
psr/http-message Version ^1.0|^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.