It is licensed and tested, with a matching source tree and no install scripts. The small dependency set does not offset the package’s limited operational safeguards.
18%
Total Score
0
100
58
83
The package includes a README and tests, but the README explicitly marks this package as deprecated and directs users to a replacement. That is a direct adoption warning despite the otherwise useful documentation.
The package has only four releases and none in the last six years; its latest registry release was in April 2020. This strongly indicates abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository being unarchived does not compensate for the absence of current activity.
Composer is used for builds, but no security scanning tools were detected. This is a hygiene gap rather than evidence that the release is unsafe by itself.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. For an authentication-related library, this is a meaningful transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laminas/laminas-math Version * | — | — |
christian-riesen/base32 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.