A thorough README and test suite make integration easier. The workflow uses read-only job permissions, but it lacks security scanning and pins neither action.
63%
Total Score
50
86
67
This is a young package, about 5 months old, with only one release and no demonstrated release cadence. That limits evidence of long-term maintenance but does not indicate abandonment by itself.
The repository recorded no commits and no active maintainers in the last 3 months, despite the package being only about 5 months old. This is the clearest sign of limited ongoing maintenance.
Composer is used for builds, providing normal package tooling, but no security scanning tools were detected. The missing scanning reduces maintenance confidence somewhat.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities. This is a hygiene concern rather than evidence that the package is unsafe.
The single workflow was fully analyzed, has read-only permissions, and has no untrusted checkout, injection, or audit findings. Both referenced actions are unpinned, leaving a modest build-reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpseclib/phpseclib Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.