The package includes tests, documentation, an Apache-2.0 license, and a matching repository. Its small audience, absent security tooling, and one unpinned workflow action add maintenance and build-trust concerns.
62%
Total Score
50
100
89
83
The repository is owned by a user account rather than an organization, so the single registry maintainer does not show broader project backing.
The repository recorded zero commits and zero active maintainers over the last three months, a meaningful sign of slowing maintenance even though release history was previously active.
The repository has zero stars, forks, and watchers, leaving little evidence of external adoption or community support; this is supporting caution rather than a verdict by itself.
Composer build tooling is present, but no security-scanning tool is configured, leaving a security-process gap for a token library.
The repository has no security policy, reducing transparency about vulnerability reporting and response for authentication-related software.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
petalbranch/petal-cipher Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.