The MIT license, matching repository, and practical README make the package transparent to integrate. It lacks tests, security scanning, and a security policy, leaving little evidence of ongoing quality control.
42%
Total Score
50
75
50
The registry lists one maintainer account. The linked project is user-owned rather than organization-backed, so there is little visible redundancy if that maintainer stops maintaining it.
This package has made only one release, on June 22, 2021, with no releases in the last 12 months. That long period without a new release is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package having received no recent maintenance.
The repository has zero stars and forks and only one watcher. Popularity is not required for health, but these counters provide no supporting evidence of community scrutiny or maintenance capacity.
The repository uses Composer, but no security-scanning tools are present. For a package involving steganography and cryptographic dependencies, that is a maintenance and quality-control gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ssitu/sod Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.