The package includes tests, release notes, a clear README, and a steady release cadence. Its license metadata conflicts with the MIT license file, while all six workflow actions are unpinned. Recent work is active but concentrated in one contributor.
72%
Total Score
90
100
88
67
The manifest declares GPL-3.0, while the artifact and repository license files are detected as MIT. The release is licensed, but the mismatch creates uncertainty for adopters.
All 35 recent commits came from one contributor, so maintenance continuity depends heavily on a single person. Organization ownership provides some handoff capacity but does not remove the concentration risk.
The project uses Composer, but no security-scanning tool was detected. This is a modest transparency and maintenance gap, not evidence of an unsafe release by itself.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
Both workflows were analyzed cleanly with no untrusted checkouts, script injection, or audit findings. However, all six action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpseclib/phpseclib Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.