The package has tests, a clear README, an MIT license, and no runtime dependencies. Recent repository activity is limited, and its workflows use unpinned actions without a security policy or scanning.
61%
Total Score
50
100
89
67
Only two releases were published, with the latest in October 2019 and none in the last 12 months. The linked repository was pushed more recently, but the registry release itself is substantially stale.
No commits or active maintainers were recorded in the last three months. The recent repository push offsets this somewhat, but it does not demonstrate ongoing development.
The repository reports no build tooling and no security scanning tooling. This is a modest transparency and maintenance concern, though the package has tests and a simple structure.
The repository has no security policy. For a cryptography-focused library, this leaves vulnerability reporting and response expectations less clear.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, and neither grants top-level write access. However, all 7 action references are unpinned, which weakens build reproducibility and update integrity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.