This release has solid transparency and implementation hygiene: it is MIT-licensed, backed by a matching organization-owned repository with tests, security policy, Dependabot, safe workflow analysis, and a recent release. However, Packagist marks tq/shamir as abandoned and points users to teqneers/shamir, which is a major adoption risk even though the repository is not archived and appears recently updated. Repository commit activity is also currently absent over the last 3 months, so the package should not be adopted under this name without confirming the replacement package and its continuity.
42%
Total Score
83
100
89
90
Packagist marks this package as abandoned and specifies teqneers/shamir as the replacement. This is a severe maintenance and adoption risk for a new dependency under tq/shamir.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although a recent release or push is visible elsewhere, the lack of measured commit activity raises maintenance-continuity concerns.
The workflow lacks top-level token permissions and relies on job-level permissions. No write permissions were detected, but explicit top-level least-privilege declarations would be clearer.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^6.4.3 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.