The source offers little verification, with no tests, a very short README, and no security policy. MIT licensing and a matching repository make the package transparent, but they do not offset the maintenance concern.
38%
Total Score
0
67
50
The package has had only two releases, both in May 2016, and none in the last 12 months. This long period without a release is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the absence of recent releases. The repository is not archived, but there is no observed recent maintenance.
The artifact includes a README, but it is only 23 characters long, and the source repository has no tests or changelog. Missing tests and changelogs are not packaging defects by themselves, but the minimal documentation weakens consumer transparency.
Composer is used for the build, which supports reproducible package management, but no security scanning tool is present. This is a hygiene gap rather than evidence that the release is unsafe.
The linked repository has no security policy. This is a modest transparency and vulnerability-reporting gap, especially for a library handling SSH connections.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version * | — | — |
phpseclib/phpseclib Version 2.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.