Tests, release notes, static analysis, and organization backing support a small, clearly identified library. CI uses unpinned actions and the repository has no security policy, leaving maintenance and workflow transparency weaker.
62%
Total Score
75
100
94
50
The package has eight releases since June 2017, but none in the last 12 months; its latest release was over two years ago. This is meaningful evidence of slowed maintenance, though the stable release history provides some maturity.
The repository recorded no commits and no active maintainers during the last three months, consistent with the long release gap. This raises abandonment risk despite the repository remaining available.
No repository security policy was found, which weakens vulnerability-reporting transparency. This is a modest concern rather than evidence that the package is unsafe.
Both workflows were fully analyzed with no injection, dangerous trigger, or audit findings, and no workflows grant top-level write access. However, all 8 action references are unpinned, leaving CI dependent on mutable action versions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
paragonie/sodium_compat Version ^1.21|^2 | — | — |
paragonie/constant_time_encoding Version ^2|^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.