The project has tests, release notes, a matching repository, and an MIT license. Its workflows use seven unpinned actions and the repository has no security policy, so pinning this exact release is preferable.
57%
Total Score
75
83
75
The package borrows the identity of paragonie/random_compat and has far fewer downloads and releases; the lookalike signal explicitly identifies it as borrowing that identity, which is a serious adoption risk even though artifact overlap is zero.
The package is mature but has had no registry release in more than two years, which is a meaningful maintenance concern despite its established history.
There were no commits and no active maintainers in the last three months, indicating that development activity has stalled recently.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented.
Both workflows were analyzed completely with no untrusted checkouts, script injection, or audit findings, but all seven referenced actions are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
defuse/php-encryption Version ^2 | — | — |
paragonie/constant_time_encoding Version ^2|^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.