Usable with caveats, especially for a security-sensitive encryption library. The repository is active and includes tests, but the package has had no registry release in over a year, all recent commits come from one maintainer, and no security policy is published.
68%
Total Score
75
100
88
75
The package has only four releases and none in the last 12 months; its latest registry release was over a year ago, which raises maintenance and freshness concerns despite the relatively short historical release intervals.
All six recent commits came from one contributor, leaving maintenance highly dependent on a single person and creating continuity risk.
Composer build tooling is present, but no security-scanning tools were detected; for an encryption library, this is a meaningful transparency gap.
No repository security policy was found. This matters more for an encryption library because users lack documented guidance for reporting vulnerabilities and receiving security fixes.
The CI workflow does not declare top-level token permissions. Although no write permissions were observed, explicit least-privilege settings would provide stronger workflow transparency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.