Recent releases, integration tests, and release notes support a maintained codebase. The sole active contributor, missing security policy, and unpinned workflow actions add ongoing maintenance and build-integrity concerns.
42%
Total Score
50
100
81
67
Packagist marks the entire package as abandoned, even though the listed replacement is the same package and the latest release is recent. Package-level abandonment is a serious dependency risk because future maintenance is not assured.
The repository is owned by an individual user rather than an organization. This does not invalidate the package, but it provides no organizational handoff capacity to offset the concentrated maintenance base.
One contributor made all commits in the last 3 months, giving the project a single-person active-maintenance base. The repository is user-owned, so there is no shown organizational backing to compensate for that concentration.
Only one commit was recorded in the last 3 months. That is evidence of some recent maintenance, but the low volume limits confidence that maintenance is durable.
Composer build tooling is present, but no security-scanning tooling was detected. The missing scanner is a modest transparency and maintenance gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpseclib/phpseclib Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.