Clear documentation, tests, and licensing make adoption straightforward. The sparse release history and six-month commit pause leave maintenance less reassuring, while workflow references are not pinned.
70%
Total Score
83
100
88
83
The package has been published since 2018 and released seven times, but only one release occurred in the last 12 months and the median interval is about 354 days, indicating a slow maintenance cadence.
The repository recorded zero commits and zero active maintainers in the last three months, indicating a recent pause in active development. The last push was about six months before collection, which weakens maintenance confidence.
The project uses Composer for builds, but no security scanning tools were detected, leaving security-maintenance coverage less transparent.
The repository has no security policy, making vulnerability reporting and response expectations less clear for a cryptographic dependency.
Both workflows were fully analyzed with no dangerous audit findings, triggers, or write permissions. However, all 8 analyzed action references are unpinned, so workflow dependencies can change without a fixed revision.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
paragonie/ecc Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.