Risky to adopt: this encryption package has had only one release and no repository activity for about five years. It is clearly licensed and documented, but its tiny project footprint, absent security policy, and uncertain repository/package connection make long-term maintenance and support doubtful.
42%
Total Score
50
100
67
90
The package has made only one release, on September 8, 2021, with no releases in the following five years. That is strong evidence of abandonment risk for a dependency handling persisted encryption.
There were zero commits and zero active maintainers during the last three months, following a last push about five years ago. This is the strongest maintenance and abandonment concern in the assessment.
The repository name does not exactly match the package name and its README does not mention the package name. Although naming differences can occur, the combination leaves the package-to-repository connection less certain.
The repository has zero stars and forks and only one watcher. Popularity is not decisive by itself, but this very small footprint provides little evidence of broad review or community support.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are present. For an encryption-focused package, the absence of security tooling is a meaningful hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
neos/flow Version >=5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.