Clear licensing, tests, release notes, and security scanning provide useful maintenance evidence. The package has had no registry release in about two years, no recent commits, and all five workflow references are unpinned, including a high-confidence unpinned container image.
65%
Total Score
75
100
94
75
The package has four releases since May 2018, with no registry release in about two years and a median release interval of about 941 days. This indicates slow maintenance and raises abandonment concerns, though it is not deprecation evidence.
There were zero commits and zero active maintainers in the three months measured. This is a meaningful sign of limited current maintenance capacity, even though the repository is not archived.
No repository security policy was found. This is a transparency gap for reporting vulnerabilities, but it is not by itself evidence that the package is unsafe to depend on.
All five analyzed action references are unpinned, and the audit found a high-confidence unpinned container image. No untrusted checkout, script injection, or broad top-level write permission was found, so this is a workflow hygiene caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
paragonie/constant_time_encoding Version ^2|^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.