Risky to adopt despite recent releases: the package README explicitly says it is abandoned and will receive no further development. The backed organization and recent repository activity provide some continuity, but only one maintainer contributed in the last three months and the repository lacks a security policy.
42%
Total Score
67
100
88
75
The package includes a README and the source repository has tests, but the README explicitly states that the package is abandoned and will receive no further development. That is a direct maintenance warning for a cryptography library.
All recent commits came from a single contributor, leaving maintenance highly concentrated. Organization backing provides some ability to hand off work, but no second active contributor is shown.
The repository had one commit from one active maintainer in the last three months. This shows some recent activity, but the volume is too low to demonstrate strong ongoing maintenance.
No repository security policy was found. For a package providing cryptographic and password-hashing functionality, this reduces transparency around vulnerability reporting and response.
All four workflows lack top-level token permission declarations, which is weaker workflow hygiene. However, none declares top-level write permissions, so this is a limited concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.1 || ^2.0 | — | — |
laminas/laminas-math Version ^3.4 | — | — |
laminas/laminas-stdlib Version ^3.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.