The package is licensed, tested, and clearly tied to its source repository, with no install-time scripts. A single registry maintainer and no security policy or scanning add operational risk for cryptographic code.
57%
Total Score
50
86
75
The package has five releases over about seven years, but none in the last 12 months and its latest release was about three years ago. This indicates substantially slowed maintenance, without showing registry deprecation.
The repository had zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository remains available and unarchived, which limits this to a maintenance concern rather than abandonment certainty.
The project uses Make and Composer, but no security-scanning tools were detected. Build tooling is present, though the absence of automated security checks is a modest concern for this package type.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities in a cryptographic library. This is a transparency and response-readiness gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version >=2.9 | — | — |
beberlei/assert Version ^3.3.2 | — | — |
paragonie/halite Version >=4.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.