The package includes a README, tests, and a matching source repository, but has little adoption and no security scanning or policy. Its single runtime dependency keeps the package simple, not maintained.
42%
Total Score
0
100
71
50
The latest release was published in April 2015, and there have been no releases in roughly 11 years. This is strong evidence of abandonment risk despite the package not being formally deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with its last push in April 2015. The long-standing lack of activity materially lowers maintenance confidence.
The repository has only 2 stars, 0 forks, and 1 watcher, providing little evidence of a broad community that could help sustain or review the package.
Composer is used for the build, but no security scanning tools are present. This is a transparency and maintenance gap, though it is less significant than the package's prolonged inactivity.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. That matters for a cryptographic package, even though this alone does not make the release unfit.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.