a PasswordHash implementation.
43%
Total Score
unhealthy
Risky: over eight years without another release, with a thin project footprint and template-level documentation.
This package has had only one release, with no release in over eight years. That is strong evidence of abandonment risk for a dependency, even though the repository remains available.
The package includes tests and release notes for this version, which provide some confidence, but its README is only 695 characters and remains generic Composer template text rather than package documentation.
The repository name matches the package, so it likely belongs to the package, but the README does not mention the package name. This weakens confidence that the source documentation is complete.
The repository has zero stars and zero forks, with only one watcher. Popularity is not decisive by itself, but this very thin footprint provides no compensating evidence for the long period without releases.
The repository has no security policy. For a password-hashing library, this is a meaningful transparency gap because users have no documented process for reporting or handling security issues.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.