Clear documentation, tests, release notes, and static analysis make adoption straightforward. The workflow should pin its two external actions, and the missing security policy leaves incident handling less clear.
82%
Total Score
100
100
94
75
The repository has no security policy, leaving the reporting and response process undocumented for a cryptographic library.
v0.4.0 is not yet at a stable major version, so breaking changes remain possible even though it is not a prerelease.
The only workflow was fully analyzed with no untrusted checkout, injection, or audit findings, but both external actions are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
paragonie/ecc Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.