Package Health

paragonie/pqcrypto_compat

Tests, a readable README, release notes, and a clean workflow make the release comparatively transparent. The organization-backed project is young and has not added a commit in three months, while its cryptography focus makes the absence of security scanning and a security policy more significant.

Latest v0.3.2PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package is young at 162 days old, with five releases and a median interval of about 1.5 days. This shows early publishing activity but provides limited evidence of long-term maintenance.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers during the last three months. Recent releases partly offset this, but the lack of observed source activity is a meaningful maintenance concern.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. That is a notable hygiene gap for a library implementing cryptographic algorithms.

Security policycaution

The repository has no security policy. For a cryptography library, this reduces transparency about how vulnerabilities and responsible disclosures are handled.

Version stabilitycaution

Version v0.3.2 is a stable, non-prerelease release, but the package remains below 1.0, so its API and behavior may still change materially.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Paragon Initiative Enterprises

Direct Dependencies

DependencyLast ReleaseScore
paragonie/sodium_compat
Version ^2

Weekly Downloads

Info

Last Published
5 months ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform