Usable with caveats: the package is clearly licensed, has a matching organizational repository, tests, and release notes. However, it has had no registry release for over two years and no recent repository commits, so maintenance may have stalled.
64%
Total Score
67
100
81
90
The package has 14 releases with a historically regular median interval, but it has had no release in over two years. That is a meaningful maintenance concern for a dependency, even though the repository remains available.
The repository recorded zero commits and zero active maintainers in the last three months. Together with the old latest release, this indicates stalled recent development.
There are no open issues and only one open pull request, with no issues or pull requests merged in the last month. This is consistent with a quiet, mature utility but provides little evidence of active upkeep.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency gap rather than a severe risk for a small library.
The repository is not archived, but its last recorded push was about two years ago, which supports the separate concern that maintenance has slowed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpseclib/phpseclib Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.