Release notes, repository tests, and a security policy provide useful transparency for a cryptography library. The organization-backed project also shows recent maintenance and active issue handling.
78%
Total Score
83
100
100
All three commits in the last three months came from one contributor, creating a continuity risk. Organization backing provides some compensation because maintenance can be handed off internally.
Both workflows were fully analyzed with no untrusted checkouts or script injection, but all 12 action references are unpinned, leaving builds exposed to upstream action changes.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-33851 paragonie/ecc is vulnerable to Security Vulnerability in versions 0 - 2.0.1. | 0 - 2.0.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
genkgo/php-asn1 Version ^2 | — | — |
paragonie/sodium_compat Version ^1|^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.