Package Health

paragonie/halite-legacy

The README explains a focused migration role, and the exact release includes notes for PHP 8 support and migration helpers. Security documentation is absent, while recent commit activity is quiet despite the repository remaining active.

Latest v0.2.0PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

Only three releases exist over roughly seven and a half years, with no releases in the last 12 months and a median interval of about three years. That slow cadence fits a legacy migration package but still raises maintenance uncertainty.

Repo commit activitycaution

There were no commits and no active maintainers during the last three months. The recent repository push partly offsets abandonment concerns, but the observed development activity remains quiet.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. For a cryptographic library, that is a meaningful transparency and maintenance gap.

Security policycaution

The repository has no security policy. This weakens vulnerability-reporting transparency for a package handling cryptographic data.

Version stabilitycaution

Version 0.2.0 is not a stable major release, which limits maturity evidence, although it is not marked as a prerelease and is a focused legacy bridge.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Paragon Initiative Enterprises

Direct Dependencies

DependencyLast ReleaseScore
paragonie/halite
Version ^4|^5
paragonie/sodium_compat
Version ^1.21
paragonie/constant_time_encoding
Version ^1|^2|^3

Weekly Downloads

Info

Last Published
1 year ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform