The project has shipped nine releases in the last 12 months and includes tests, a matching repository, and a clear MIT license. Maintenance has paused for three months, security scanning is absent, and all four workflow actions are unpinned.
68%
Total Score
75
100
89
67
The repository recorded no commits and no active maintainers during the past three months, which is a real maintenance concern even though the latest release was recent.
The repository has no stars or forks and only one watcher. Popularity is supporting evidence rather than a verdict, but this provides little external evidence of maturity.
Composer build tooling is present, but no security scanning tools were detected, leaving security-maintenance coverage thin.
The repository has no security policy, making the vulnerability reporting and response process unclear for a cryptographic package.
The only workflow was fully analyzed with no dangerous triggers or audit findings, but all four action references are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nostriphant/nip-01 Version ^3.0 | — | — |
phpseclib/phpseclib Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.