The package is small and easy to inspect, with tests, a README, and no install-time scripts. Its only release was about eight years ago, and the repository has no security policy or security scanning, so future support is uncertain.
58%
Total Score
100
100
78
83
There has been only one release, published about eight years ago, with no releases in the last 12 months. This is a meaningful maintenance and abandonment concern despite the package remaining available.
The repository has no stars or forks and only one watcher. Popularity is not required for a healthy package, but these counters provide little supporting evidence of active community use or review.
Composer is used for builds, but no security-scanning tools are configured. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository is not archived, but its last push was about eight years ago, consistent with the stale release history. The non-archived status prevents this from being a severe abandonment signal.
The repository has no security policy. For an encryption library, the absence of a documented vulnerability-reporting path is a relevant transparency gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.