This is a small, stable Laravel RSA package with a clear MIT license, a matching and recently pushed source repository, no registry deprecation, no install-time lifecycle scripts, and releases as recently as September 2026. However, its maturity and maintenance evidence are limited: the repository contains only eight files, has no tests, changelog, security policy, security scanning, or active commits in the last three months, and has very low adoption indicators. It may be usable, but developers should treat it as a lightly maintained dependency and review its cryptographic implementation and update responsiveness before relying on it for security-sensitive functionality.
68%
Total Score
50
50
83
80
There are three runtime dependencies, including PHP and two package-specific libraries, with no development dependencies. The runtime dependency count is modest, but the absence of development dependencies also aligns with the lack of visible test infrastructure.
Only one registry account has publish access. This is a concentration risk for continuity, though the matching source repository and recent release activity provide some compensation.
The artifact and repository each contain only eight files, consisting primarily of source, configuration, and documentation. This is consistent with a small package but provides limited evidence of engineering and validation depth.
The package includes a useful README and the repository uses GitHub Releases, but it has no tests or changelog. For a cryptographic integration package, the absence of repository tests is a meaningful maintenance and validation gap.
The repository is owned by an individual user rather than an organization, so continuity depends substantially on one project owner. The package and repository names align, providing useful identity consistency but not organizational redundancy.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
seffeng/cryptlib Version >=0.1 | — | — |
seffeng/arr-helper Version >=0.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.