The project has one active maintainer and all five recent commits come from that person, limiting continuity. It has tests, a security policy, frequent stable releases, and read-only workflow permissions; the two unpinned actions are a minor supply-chain hygiene gap.
78%
Total Score
67
100
93
83
The repository is owned by an individual user rather than an organization, so the concentrated maintainer activity represents a genuine single-person continuity risk.
One contributor made all five recent commits, creating a real continuity risk for a security-sensitive library; no organizational backing is shown to offset that concentration.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and maintenance gap for a cryptography package.
The only workflow was fully analyzed, uses read-only permissions, and has no reported audit findings. Both action references are unpinned, which is a minor reproducibility and supply-chain hygiene weakness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pohoc/crypto-sm Version ^0.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.