JSON object encryption library
72%
Total Score
caution
Usable with caveats: recent maintenance is concentrated in one contributor and repository security hygiene is limited.
Ten runtime dependencies, including cloud SDKs and encryption libraries, create meaningful dependency surface for this security-sensitive library, but the profile is coherent with its stated cloud integrations.
All two recent commits came from one contributor. Organizational ownership reduces the risk somewhat, but no second recent contributor is shown to provide maintenance redundancy.
The repository recorded two commits in the last three months, showing recent activity but a relatively light maintenance pace.
Composer build tooling is present, but no repository security-scanning tool was detected. For an encryption library, that is a meaningful hygiene gap rather than a release blocker.
The repository has no security policy. That weakens vulnerability-reporting transparency for a library handling encryption and cloud key-management integrations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version ^6.4||^7.0 | — | — |
aws/aws-sdk-php Version ^3.209 | — | — |
vkartaviy/retry Version ^0.2 | — | — |
google/cloud-kms Version ^1.20 | — | — |
defuse/php-encryption Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.