The repository is licensed, tested, and not archived, with a small dependency surface. However, source activity has been inactive for over three years and the package has been replaced, leaving this release unsuitable for a new dependency.
18%
Total Score
25
63
75
Packagist marks the entire package as abandoned and names oops/totp-authenticator as its replacement, which is a direct adoption warning rather than a cosmetic gap.
The latest registry release was over six years ago, with no releases in the last 12 months and only five releases overall; this indicates a stale release line.
The repository recorded no commits and no active maintainers in the last three months, reinforcing the risk that maintenance has stopped.
There was no issue or pull-request activity in the last month, while one issue and two pull requests remain open; this provides no evidence of active resolution.
The linked repository name does not match the package and its README does not mention the package, so the package-to-source relationship is less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
paragonie/constant_time_encoding Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.