This release appears generally healthy and suitable for consideration: it is licensed under MIT, has a substantial README and changelog, is backed by a matching organization-owned repository with repository tests, has a strong recent release cadence, is not deprecated or archived, and uses read-only workflow permissions without detected dangerous workflow patterns. The main concern is that the repository recorded zero commits and zero active maintainers in the last 3 months despite frequent releases, which weakens evidence of ongoing development; the single registry maintainer and lack of security-scanning tooling are additional, lesser transparency concerns. Validate the release contents and maintenance expectations before adopting it for security-sensitive encryption functionality.
77%
Total Score
88
89
90
The package uses post-install-cmd and post-update-cmd scripts, which increase install-time execution exposure; no provided signal shows these scripts are dangerous, so this is a moderate hygiene concern rather than a severe finding.
The repository recorded 0 commits and 0 active maintainers over the last 3 months, which is concerning because development activity appears to have collapsed despite 20 releases in the last year.
The repository has only 1 star and 0 forks, indicating limited external adoption; this is supporting context rather than a decisive health problem because the package shows active release activity and organization backing.
Composer build tooling is present, but no security-scanning tools were detected; for an encryption-focused package this is a meaningful hygiene gap, though it is not evidence of unsafe code by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version 3.* | — | — |
doctrine/dbal Version 4.* | — | — |
symfony/config Version ^7.0 || ^8.0 | — | — |
doctrine/persistence Version 3.* | — | — |
precision-soft/symfony-console Version ^4.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.