Pure-PHP SSHSIG signing and verification, compatible with ssh-keygen -Y.
67%
Total Score
caution
Usable with caveats: a high-confidence workflow audit issue and single-contributor maintenance raise adoption risk.
The repository is owned by an individual rather than an organization, so the single-contributor concentration represents a real handoff risk.
The package is young at 88 days with four releases, but releases occurred about every two days and activity is recent. The limited history still leaves less evidence of long-term maintenance.
All 12 recent commits came from one contributor, leaving maintenance and review capacity concentrated in a single person without organizational backing.
All workflows were analyzed, but a high-confidence bot-conditions finding reports spoofable actor context in the Dependabot auto-merge workflow; that workflow also has top-level write permissions, while two of five action references are unpinned.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.