The package includes a matching repository, clear licensing, usage documentation, and repository tests. Its small dependency surface does not offset the lack of activity and project-level abandonment; use a maintained replacement or fork instead.
15%
Total Score
0
50
75
Packagist marks the entire package as abandoned, with no replacement named. This is a direct warning that the published package should not be adopted for new dependencies.
The package has had no releases in more than 10 years and none in the last 12 months. Its earlier release cadence does not compensate for this prolonged inactivity.
The repository recorded zero commits and zero active maintainers in the last 3 months. Together with the archived status, this confirms that maintenance has stopped rather than merely slowed.
The linked repository is archived, and its last push was in May 2016. An archived source project is a severe abandonment risk for a security-sensitive token library.
The repository has no security policy. For a library handling encrypted tokens, this is a transparency gap, although the archived and deprecated status are the more serious concerns.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.