The dependency footprint is minimal and the repository matches the package name. Its lack of security policy and scanning leaves limited evidence of ongoing safeguards, while the compact source tree offers little consumer documentation.
40%
Total Score
100
64
50
The package has had no release in nearly seven years: its latest release was published on October 24, 2019, with zero releases in the last 12 months. This is strong evidence of abandonment risk.
The published artifact has no README, which reduces guidance for consumers of this library. Missing tests and a changelog are expected packaging gaps and do not lower the score here.
Composer is used for the build, and the package has only one runtime dependency, which limits complexity. However, no security scanning tooling is reported, providing little compensating evidence for ongoing security maintenance.
The repository is not archived, but it was last pushed on October 24, 2019, so its active maintenance appears to have stopped nearly seven years ago.
The repository has no security policy, leaving no documented channel or process for handling security reports. This is a transparency gap for a cryptographic library.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.