The package is well documented and has a focused dependency set. Its MIT licensing, release notes, repository tests, and Dependabot scanning provide useful transparency and maintenance support.
82%
Total Score
75
100
100
83
All 31 recent commits came from one contributor, leaving maintenance capacity concentrated in a single person and increasing continuity risk.
No repository security policy was found, which reduces the transparency of vulnerability reporting and response expectations for a cryptography library.
The only workflow was fully analyzed with no high-confidence audit findings or untrusted checkouts, but both action references are unpinned, so their versions can change without a repository update.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
paragonie/halite Version ^5.1 | — | — |
paragonie/hidden-string Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.