The repository matches the package, documents installation and usage, and avoids install-time scripts. Its narrow scope and minimal runtime footprint reduce integration complexity, but it is a poor fit where clear licensing or ongoing fixes are required.
40%
Total Score
50
100
75
75
Neither the package metadata nor the linked repository contains a recognized license declaration or license file. That leaves redistribution and use rights unclear for developers adopting the dependency.
The package has only one release, published over 10 years ago, with no releases in the last 12 months. This is strong evidence of an inactive release line, although the stable 1.0 version may reflect a deliberately finished small project.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package having received no updates since August 2016. The small scope may reduce the need for frequent changes, but it does not provide evidence of ongoing maintenance.
The repository has no security policy, so there is no documented channel or process for reporting vulnerabilities. This is a transparency gap, particularly for a package implementing encryption-related functionality.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.