The license, focused package contents, and organizational ownership improve transparency. Its one-day history, absent recent commit activity, missing tests, and lack of a security policy leave maintenance and review confidence limited.
68%
Total Score
75
100
81
83
A substantial README and GitHub release are present. Tests and a changelog are absent, but those are not expected in the published artifact; the missing repository test evidence still limits confidence for an encryption library.
The package is only 1 day old with two releases, so there is not enough history to demonstrate sustained maintenance or stability.
No commits or active maintainers were recorded in the past 3 months. Because the project is only 1 day old, this is partly explained by its age but still provides no established maintenance track record.
Composer build tooling is present, but no security-scanning tooling was detected, which is a meaningful hygiene gap for a package implementing encryption handlers.
The repository has no security policy, leaving no documented path for reporting vulnerabilities in security-sensitive code.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.