MIT licensing, a focused dependency set, and comprehensive tests make the codebase easier to evaluate. The small release history, missing security policy, and unpinned workflow actions leave maintenance and build-integrity questions for a cryptography library.
64%
Total Score
75
50
This package has only one release, published 484 days ago, with no releases in the last 12 months. Repository activity provides some compensation, but the registry history still suggests limited release maturity.
Composer build tooling is present, but no security scanning tools are reported, leaving a meaningful security-process gap for this type of library.
The repository has no published security policy, which reduces transparency for reporting and handling vulnerabilities in a cryptography-focused package.
Version 0.0.1 is not a stable major release, so compatibility and API maturity are less established than for a mature stable package.
Both workflows were analyzed without dangerous triggers or audit findings, but all 3 action references are unpinned, making workflow dependencies less reproducible and harder to verify over time.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tourze/tls-common Version 0.0.* | — | — |
phpseclib/phpseclib Version ^3.0.43 | — | — |
paragonie/sodium_compat Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.