The small, single-maintainer project has tests, documentation, and a clear MIT license. Its 0.x version and lack of security scanning increase the maintenance risk for a cryptography-related dependency.
43%
Total Score
25
71
50
The latest release was in January 2019, with no releases in over seven years. This is strong evidence that the package is no longer actively maintained, although it is not registry-deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing prolonged inactivity.
The registry lists one maintainer, which limits the visible maintainer base. The repository is user-owned rather than organization-backed, and the lack of recent activity provides no compensating maintenance evidence.
Composer build tooling is present, but no security-scanning tool was detected. That is a meaningful hygiene gap for a cryptography-related package.
The repository has no security policy. For a package implementing encrypted HTTP content, this reduces transparency and makes vulnerability reporting less clear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spomky-labs/base64url Version ^1.0 | — | — |
spomky-labs/php-aes-gcm Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.