Risky to adopt without strong justification: it has had no release or repository update since January 2018. The small, focused package includes tests, a README, an MIT declaration, and no install scripts, but its maintenance and security transparency are too weak for a dependable long-term dependency.
45%
Total Score
50
100
75
88
The package has only one release, published in January 2018, with no releases in the last 12 months; this is strong evidence that maintenance has effectively stopped.
Only one registry publishing account is listed, leaving little visible publishing redundancy; this concern is reinforced by the repository's long inactivity.
Composer build tooling is present, but no security scanning tools are configured; this is a modest transparency gap, especially for a package handling encryption.
The repository is not formally archived, but its last push was in January 2018, roughly 8 years ago, which indicates prolonged inactivity despite the non-archived status.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported for a cryptographic package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.