The package includes clear documentation, release notes for this version, repository tests, and security scanning. GitHub Actions references are all unpinned, and recent work is concentrated in one contributor, so maintenance and build reproducibility deserve attention.
82%
Total Score
80
100
100
75
All two recent commits came from one contributor, creating concentration risk; organization ownership provides some handoff capacity but no second recently active contributor is shown.
Only two commits were made in the last 3 months, so recent source activity is modest despite the recent release history.
The repository has no published security policy, leaving vulnerability reporting and response expectations less transparent for a cryptography-related library.
All four workflows were analyzed without findings or untrusted-code sinks, but all 12 action references are unpinned, leaving build actions exposed to reference changes.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-133621 paragonie/sodium_compat is vulnerable to Improper Input Validation in versions 1.0.0 - 1.24.0 and 2.0.1 - 2.5.0. | 1.0.0 - 1.24.02.0.1 - 2.5.0 | Medium |
AIKIDO-2025-11010 paragonie/sodium_compat is vulnerable to Incomplete List of Disallowed Inputs in versions 0.0.1 - 1.23.0 and 2.0.0 - 2.4.0. | 0.0.1 - 1.23.02.0.0 - 2.4.0 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.