It has a clear MIT license, a usable README, and no install-time scripts. Its two-release history stopped over seven years ago, while the repository has no security scanning, making future maintenance uncertain.
58%
Total Score
50
78
75
The package has only two releases, both from February 2019, with no releases in the last 12 months. This long period without a release materially raises abandonment risk.
There are no open issues or pull requests and no recent issue or pull-request activity. Combined with the old release history, this is consistent with a dormant project rather than active maintenance.
The repository has four stars and one fork, indicating a small user and contributor footprint. Popularity is only supporting evidence, but this provides little evidence of a broad maintenance community.
Composer build tooling is present, but no security scanning tools were detected. For a password-hashing library, that missing security automation is a meaningful hygiene concern.
The repository has no security policy. That limits the project's documented process for reporting and handling vulnerabilities, which matters for a security-sensitive hashing package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.