The repository has no security policy and all three workflow actions are unpinned, leaving avoidable maintenance and build-integrity gaps. MIT licensing, tests, documentation, and a small dependency surface provide useful compensating evidence.
55%
Total Score
50
100
88
75
Only two releases were published, both within roughly one hour, and there have been no releases in about 14 months. This indicates a young project with no recent registry maintenance.
There were no commits and no active maintainers in the last three months, while the last repository push was about 14 months ago. This is meaningful evidence of slowed maintenance.
Composer is used for the build, but no security scanning tools are configured. That leaves a modest transparency and maintenance gap for a cryptography-related package.
The repository has no security policy. For an encryption library, the absence of a documented vulnerability-reporting process is a real transparency gap.
Both workflows were analyzed successfully with no dangerous triggers, sinks, or audit findings, but all three action references are unpinned. Pinning them would reduce avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.