Project analysis collected March 18, 2026 (139 days ago).

The State of Cryptography

Cryptographic library adoption across 11 package ecosystems

0:1weak or deprecated crypto downloads for every 1 PQC downloadRatio of weak/deprecated crypto library downloads (MD5, SHA-1, DES, RC4, RSA-PKCS1) to post-quantum (ML-KEM, ML-DSA) downloads
355
Crypto Libraries Tracked
6.4B
Measured Downloads / Month
+ 743.1M modelled
735
Crypto CVEs
11
Ecosystems
2.2M+
Packages Analyzed

NIST Post-Quantum Deadlines

NIST IR 8547 transition deadlines for quantum-vulnerable public-key algorithms

0
Days until 2030
Deprecate quantum-vulnerable asymmetric crypto
3
Years
5
Months
0
Days

NIST targets deprecation of quantum-vulnerable public-key algorithms (RSA, ECDSA, ECDH, DSA) by this date. Symmetric ciphers (AES) and hash functions (SHA-2, SHA-3) are unaffected.

Click for details
0
Days until 2035
Disallow quantum-vulnerable asymmetric crypto
8
Years
5
Months
1
Days

Quantum-vulnerable public-key algorithms must be fully replaced. Symmetric crypto (AES-128/256) and hash functions remain approved.

Click for details
How we classify
Weak
Modern
PQC
Weak / Deprecated

Algorithms with known cryptanalytic breaks (MD5, SHA-1, DES, RC4, Blowfish) or unmaintained implementations with known CVEs. These should be replaced regardless of quantum computing timelines.

e.g. MD5, SHA-1, DES, 3DES, RC4, Blowfish

Modern / Current-Gen

Actively maintained cryptographic libraries using current-generation algorithms. Includes both quantum-safe symmetric crypto (AES-256, SHA-256, ChaCha20) and quantum-vulnerable asymmetric crypto (RSA, ECDSA, Ed25519). The asymmetric algorithms in this tier are targets for NIST's 2030/2035 PQC transition.

e.g. AES-GCM, SHA-256, ECDSA, Ed25519, Argon2, bcrypt

Post-Quantum

Implementations of NIST-standardized post-quantum algorithms (ML-KEM, ML-DSA, SLH-DSA) that resist both classical and quantum attacks. These are the replacements for RSA and ECDSA mandated by NIST IR 8547.

e.g. ML-KEM (Kyber), ML-DSA (Dilithium), SLH-DSA (SPHINCS+)

Note: The "Modern" tier includes both quantum-safe symmetric crypto (AES-256, SHA-256) and quantum-vulnerable asymmetric crypto (RSA, ECDSA). The NIST 2030/2035 deadlines apply only to the asymmetric algorithms. Symmetric crypto and hashes remain approved beyond 2035.

Weak / Deprecated
Broken or deprecated algorithms (MD5, SHA-1, DES, 3DES, RC4, Blowfish)
0
downloads / month
14.5% of total
Top packages
rsa284.6M
node-forge150.9M
crypto-js75.8M
md562.0M
ripemd16056.6M
Click for top packages
Modern / Current-Gen
Current-generation, maintained implementations (AES-GCM, SHA-256, ECDSA, Ed25519, Argon2, bcrypt)
0
downloads / month
85.5% of total
Top packages
cryptography1.4B
PyJWT675.2M
jose385.8M
@noble/hashes260.4M
pynacl232.5M
Click for top packages
Post-Quantum
Quantum-resistant per NIST FIPS 203/204/205 (ML-KEM (Kyber), ML-DSA (Dilithium), SLH-DSA (SPHINCS+))
0
downloads / month
0.1% of total
Top packages
Click for top packages

Crypto Health by Ecosystem

Of 65.7K packages using cryptography (from 2,170,994 analyzed), here is where they stand by package count - click an ecosystem for details

12.5K
packages using vulnerable crypto
19.0%
of crypto-using packages
52.9K
secured but not PQC ready
80.5%
of crypto-using packages
353
PQC ready
0.5%
of crypto-using packages
All Ecosystems Combined
19.0%
80.5%
Vulnerable
Secured (not PQC)
PQC Ready
crates.io
29.2K packages15.3% vulnerable
Go Modules
13.3K packages24.3% vulnerable
npm
10.2K packages30.7% vulnerable
PyPI
5.0K packages4.0% vulnerable
Maven Central
2.0K packages45.7% vulnerable
NuGet
1.9K packages10.7% vulnerable
RubyGems
1.3K packages6.3% vulnerable
Packagist
1.2K packages15.4% vulnerable
pub.dev
862 packages0.0% vulnerable
CocoaPods
357 packages14.6% vulnerable
Hex
317 packages0.9% vulnerable

PQC Adoption Projection(measured: July 2026)

Data transparency: This chart has one real measurement (July 2026). All prior data points are mathematical estimates derived from the current snapshot, not historical measurements. Dashed lines indicate estimated values. The solid segment at the right marks the actual measured data point. Historical trend tracking begins with this census.
Measured: Weak Crypto Share
13.7%
of total downloads (July 2026)
Measured: PQC Adoption
0.060%
of total downloads (July 2026)

Dashed lines = mathematical estimates from a single snapshot. Solid dot = actual measurement. PQC adoption plotted on right axis (different scale) due to early-stage adoption levels. Historical trend data collection begins with the July 2026 census. Future runs will add real data points.

The PQC Gap

Download volume by cryptographic tier - click a segment for details

Weak 14.5%
Modern 85.5%

PQC Migration Projection

Projected PQC adoption using logistic S-curve model (Bass diffusion) with NIST deadline markers

Current PQC Share
0.4278%
of weak + PQC downloads
Moderate Scenario at 2030
21.8%
projected PQC adoption by NIST deprecation
Moderate Scenario at 2035
59.1%
projected PQC adoption by full disallowance
Conservative
S-curve k=5%
50% by ~2109 (999 months)
2030: MISSES2035: MISSES
Moderate
S-curve k=8%
50% by ~2031 (69 months)
2030: MISSES2035: MEETS
Optimistic
S-curve k=12%
50% by ~2029 (38 months)
2030: MEETS2035: MEETS

Projections use a logistic growth model (S-curve), standard for technology adoption forecasting (Bass, 1969). Unlike compound growth models which imply unbounded exponential expansion, S-curves model realistic adoption with an inflection point and saturation ceiling. Actual adoption will depend on regulatory mandates, tooling maturity, and industry coordination.

Category Analysis

Weak/modern/PQC breakdown by cryptographic use case - click a category for package details

General
2.5B8.9% weak
JWT
1.6B0.9% weak
Hashing
1.1B25.3% weak
Signing
654.3M44.2% weak
KDF / Password
483.2M0.1% weak
Encryption
444.1M49.5% weak
TLS / SSH
294.9M0.1% weak

Migration Paths

Total gap: 76.9M downloads/mo

Weak packages paired with recommended replacements, sorted by migration gap - click for details

node-forgeto@noble/curves
General
150.9M
99.5M
Migration gap: 51.5M
paragonie/random_compattorandom_bytes()
General
11.0M
0
Migration gap: 11.0M
Portable.BouncyCastletoBouncyCastle.Cryptography
General
13.9M
10.6M
Migration gap: 3.3M
org.apache.santuario:xmlsectoorg.bouncycastle:bcprov-jdk18on
Signing
3.3M
0
Migration gap: 3.3M
Microsoft.Azure.KeyVaulttoAzure.Security.KeyVault.Keys
General
5.7M
3.1M
Migration gap: 2.7M
org.apache.wss4j:wss4j-ws-security-commontoorg.bouncycastle:bcprov-jdk18on
General
2.5M
0
Migration gap: 2.5M
github.com/dgrijalva/jwt-gotogithub.com/golang-jwt/jwt/v5
JWT
10.7M
9.2M
Migration gap: 1.6M
ircmaxell/random-libtorandom_bytes()
General
524.8K
0
Migration gap: 524.8K

Ecosystem Breakdown

Cryptographic library adoption by download volume across 10 ecosystems - hover slices, click for packages

npm
2.3B
jose
385.8M
@noble/hashes
260.4M
jsonwebtoken
205.1M
node-forge
150.9M
tweetnacl
136.4M
hash.js
106.5M
@noble/curves
99.5M
sha.js
89.5M
PyPI
3.3B
cryptography
1.4B
PyJWT
675.2M
rsa
284.6M
pynacl
232.5M
bcrypt
200.5M
paramiko
151.5M
pycryptodome
97.8M
argon2-cffi
70.0M
Go Modules(modelled)
231.6M
crypto/tls
38.0M
crypto/rand
25.0M
crypto/aes
22.0M
crypto/sha256
18.0M
crypto/cipher
16.0M
crypto/x509
15.0M
crypto/hmac
14.0M
crypto/ecdsa
12.0M
Maven Central(modelled)
183.2M
software.amazon.awssdk:kms
89.0M
com.nimbusds:nimbus-jose-jwt
14.7M
org.springframework.security:spring-security-crypto
11.5M
io.netty:netty-handler
11.4M
com.google.cloud:google-cloud-kms
10.1M
org.signal:libsignal-client
5.8M
com.squareup.okhttp3:okhttp
4.8M
com.azure:azure-security-keyvault-keys
4.3M
crates.io(90d/3)
687.9M
sha2
68.5M
rustls
58.9M
zeroize
49.3M
ring
47.9M
subtle
47.1M
hmac
38.4M
sha1
35.6M
md-5
24.4M
Packagist
62.9M
firebase/php-jwt
11.5M
paragonie/random_compat
11.0M
phpseclib/phpseclib
10.3M
lcobucci/jwt
7.8M
symfony/password-hasher
4.7M
spomky-labs/pki-framework
4.7M
defuse/php-encryption
4.7M
paragonie/sodium_compat
3.8M
NuGet(modelled)
308.1M
Microsoft.IdentityModel.Tokens
114.5M
System.IdentityModel.Tokens.Jwt
104.3M
Microsoft.AspNetCore.DataProtection
29.7M
Portable.BouncyCastle
13.9M
BouncyCastle.Cryptography
10.6M
MimeKit
8.3M
Microsoft.Azure.KeyVault
5.7M
Azure.Security.KeyVault.Keys
3.1M
RubyGems(modelled)
20.3M
jwt
6.6M
bcrypt
3.4M
net-ssh
3.1M
rotp
1.1M
ed25519
1.0M
encryptor
1.0M
json-jwt
890.2K
openssl
753.3K
Hex(90d/3)
4.9M
plug_crypto
1.5M
jose
891.0K
joken
543.2K
comeonin
528.6K
bcrypt_elixir
408.0K
cloak
251.4K
cloak_ecto
205.7K
guardian
185.2K
pub.dev
5.6M
pointycastle
2.7M
dart_jsonwebtoken
1.1M
encrypt
714.1K
cryptography
469.8K
basic_utils
201.3K
pinenacl
117.1K
hashlib
73.3K
jose
56.3K

Ecosystem Readiness Radar

Modern + PQC adoption percentage across all 10 ecosystems

100%Hex
100%pub.dev
96.2%RubyGems
92.5%Maven Central
91.3%NuGet
90.8%Go Modules
90.6%PyPI
87.8%crates.io
77.8%Packagist
75.7%npm

Top Packages by Downloads

Measured download counts only - click a bar for details, filter by tier

Largest modelled figures, not ranked above

These registries publish no download counts. Each figure is a proxy signal multiplied by a constant - Go uses GitHub stars x 1,000, Maven versionCount x 50,000, and NuGet and RubyGems divide a lifetime cumulative total by an assumed 36 and 120 months. They are shown for scale and are not comparable with the measured counts above.

Microsoft.IdentityModel.Tokensnuget
~114.5M
System.IdentityModel.Tokens.Jwtnuget
~104.3M
software.amazon.awssdk:kmsmaven
~89.0M
crypto/tlsgo
~38.0M
Microsoft.AspNetCore.DataProtectionnuget
~29.7M
crypto/randgo
~25.0M

GitHub Popularity vs Downloads

Stars indicate developer interest, downloads indicate deployment

Package
GitHub Stars
Downloads/mo
jsonwebtokenmodern
18.2K
205.1M
crypto-jsweak
16.4K
75.8M
firebase/php-jwtmodern
9.8K
11.5M
josemodern
7.7K
385.8M
josemodern
7.7K
77.0K
josemodern
7.7K
891.0K
josemodern
7.7K
56.3K
cryptographymodern
7.7K
1.4B
cryptographymodern
7.7K
469.8K
rustlsmodern
7.5K
58.9M
PyJWTmodern
5.7K
675.2M
phpseclib/phpseclibmodern
5.6K
10.3M
node-forgeweak
5.3K
150.9M
ringmodern
4.1K
47.9M
defuse/php-encryptionmodern
3.9K
4.7M
jwtmodern
3.7K
6.6M
pycryptodomemodern
3.2K
97.8M
sha2modern
2.2K
68.5M
ellipticmodern
1.8K
58.2M
bcryptmodern
1.5K
200.5M

Project Crypto Exposure

Which popular open source projects depend on weak cryptography?

2,170,994 packages analyzed across 11 ecosystems
511
top projects analyzed in detail for cryptographic dependencies
65,686 packages use cryptography: 12,465 weak (19.0%), 52,868 modern (80.5%), 353 PQC (0.54%)
Deep Scan Finding

Dependency analysis detected cryptographic usage in 65,686 packages. Deep source-level scanning (cryptoserve scan) on a sample of 20 top projects found 4x more crypto patterns -- including stdlib calls, algorithm constants, and TLS configurations invisible to dependency matching.

19.0%
Use Weak Crypto
Depends on broken or deprecated crypto (MD5, SHA-1, DES, RC4)
80.5%
Modern Only
Uses only current-generation crypto with no weak dependencies
0.54%
PQC Ready
Has at least one post-quantum dependency (ML-KEM, ML-DSA, or SLH-DSA)
ProjectDownloads/moPostureCrypto DepsWeak / Modern / PQC
react
npm
62.0MNo Crypto
>
lodash
npm
52.0MNo Crypto
>
axios
npm
48.2MNo Crypto
>
requests
PyPI
42.0MModern
1M
>
express
npm
34.2MWeak
2W
>
webpack
npm
28.4MMixed
1W
>
next
npm
22.1MModern
2M
>
spring-boot
Maven Central
18.4MMixed
1W1M
>
jsonwebtoken
npm
18.4MMixed
1W1M
>
django
PyPI
12.8MModern
2M
>
tokio-rs/tokio
crates.io
12.6MNo Crypto
>
fastapi
PyPI
9.2MModern
2M
>
flask
PyPI
8.4MModern
1M
>
hyper-rs/hyper
crates.io
8.2MModern
2M
>
apache/kafka
Maven Central
6.8MMixed
1W1M
>
laravel/framework
Packagist
6.2MModern
2M
>
gin-gonic/gin
Go Modules
4.2MMixed
1W1M
>
actix/actix-web
crates.io
3.4MModern
2M
>
IdentityServer4
NuGet
3.4MModern
2M
>
symfony/security-bundle
Packagist
2.8MMixed
1W1M
>

Research Insights

Analytical findings and PQC readiness assessment - click findings for details

Risk Metrics
Exposure Index
1.0B
weak downloads/mo
Annual Exposure
12.3B
estimated/yr
CVE Density
0.12
per 1M downloads
Migration Urgency
HIGH
14.29% critical advisories
NIST 2030 Deadline
1,253
days remaining (3.4 yrs)
PQC Adoption
0.1%
of crypto downloads
Weak:PQC Ratio
233:1
weak per PQC download
Packages Tracked
355+
across 11 ecosystems
Ecosystem Health Scores
Hex
1000.04%
pub.dev
1000%
Go Modules
99.59.2%
RubyGems
96.23.77%
Maven Central
92.57.53%
NuGet
91.38.71%
PyPI
90.79.37%
crates.io
89.912.23%
Packagist
77.822.17%
npm
7624.29%
Score (0-100)Weak %
PQC Readiness Assessment
Weighted by actual PQC adoption. Aligned to QRAMM dimensions.
0/ 100
Grade: C
PQC Readiness Score
ITRPQC Adoption Rate
2/100 (50%)
CVIWeak Crypto Decline
86/100 (20%)
ITRPQC Library Availability
80/100 (15%)
DPEModern Crypto Strength
100/100 (10%)
CVIVulnerability Density
93/100 (5%)
Assessed against the QRAMM (Quantum Readiness Assurance Maturity Model) framework dimensions:
CVICryptographic Visibility & Inventory
SGRMStrategic Governance & Risk Management
DPEData Protection Engineering
ITRImplementation & Technical Readiness
Critical Findings
CRITICAL

NIST 2030 PQC migration deadline

3 yrs, 158 days

1,253 days (3 yrs, 158 days) remain until NIST targets deprecation of RSA, ECDSA, and other quantum-vulnerable algorithms. Organizations should have migration plans finalized and implementation underway well before this date to account for testing and validation cycles.

CRITICAL

Annual supply chain exposure to weak cryptography

~12.3B/year

Extrapolating monthly weak crypto downloads to annual: ~12.3B package installations per year incorporate deprecated cryptographic primitives (MD5, SHA-1, DES, RC4, unmaintained libraries). Note: download counts include CI/CD and transitive dependencies and may overstate direct application usage.

High Priority
HIGH

Weak-to-PQC download ratio

233:1

For every 1 post-quantum crypto download, there are 233 downloads of weak/deprecated cryptographic packages. Note: PQC replaces quantum-vulnerable public-key algorithms (RSA, ECDSA), not symmetric crypto or hashes. This ratio indicates how far behind PQC adoption trails legacy usage.

HIGH

PQC adoption critically low before NIST deadline

0.1000%

Post-quantum cryptography accounts for only 0.1000% of tracked downloads, with 1,253 days remaining until the NIST 2030 deprecation deadline. At current adoption rates, the ecosystem is not on track for a timely transition.

HIGH

Security advisory severity distribution

7 total

Of 7 crypto-related advisories among the 2,000 most recently reviewed GitHub advisories: 1 critical (14.3%), 2 high (28.6%), 1 medium, 3 low. Critical and high severity advisories require immediate attention in dependency audits.

Additional Findings
MEDIUM

Downloads using deprecated cryptography

14.5%

14.5% of all tracked cryptographic package downloads (1.0B/month) rely on weak or deprecated algorithms including MD5, SHA-1, DES, RC4, and unmaintained libraries.

MEDIUM

Single package concentration in weak crypto

27.7% of weak

rsa accounts for 27.7% of all weak crypto downloads (284.6M/month). Migrating this single dependency away from deprecated algorithms would substantially reduce ecosystem exposure.

MEDIUM

npm has higher weak crypto usage than PyPI

24.3%

npm weak crypto: 24.3% of downloads. PyPI weak crypto: 9.4% of downloads. npm shows a higher concentration of deprecated cryptographic libraries, indicating a greater need for migration tooling and awareness in that ecosystem.

MEDIUM

Cryptographic CVE density across ecosystems

0.12 per 1M

735 crypto-related CVEs mapped across 6.4B measured monthly downloads yields a density of 0.12 CVEs per million downloads. Ecosystems that publish no download counts are excluded from the denominator rather than estimated into it. Each vulnerability in a widely-used package multiplies exposure across dependent applications.

INFO

Leading modern cryptography package

1.4B/mo

cryptography leads modern crypto adoption with 1.4B/month (22.9% of modern tier). Modern packages provide audited, constant-time implementations but still require future PQC migration for quantum-vulnerable algorithms like ECDSA and RSA.

Quantum Threat & Migration

Algorithm vulnerability timeline, PQC implementation availability, and recommended actions

AlgorithmEst. Quantum Break
RSA-2048CRITICAL
NIST deprecation by 2030
ECDSA P-256CRITICAL
NIST deprecation by 2030
AES-128LOW
No practical quantum threat; CNSA 2.0 recommends AES-256 for defense systems
AES-256SAFE
N/A -- quantum-resistant at current key sizes
SHA-256SAFE
N/A -- not considered quantum-vulnerable by NIST
ML-KEM (Kyber)SAFE
N/A
ChaCha20-Poly1305SAFE
N/A -- quantum-resistant at current key sizes

Vulnerability Landscape

Click rows and bars for detailed breakdowns

NVD CVEs by Category
735 total
CWEDescriptionCount
CWE-327Use of a Broken or Risky Cryptographic Algorithm398
CWE-326Inadequate Encryption Strength336
CWE-328Use of Weak Hash1

Click a row for details

GitHub Advisories by Severity
7 of 2,000 reviewed

Click an arc or badge for details

By Ecosystem
NuGet
3
PyPI
2
composer
2
npm
1
rust
1

HTML: Self-contained report with Chart.js visualizations | JSON: Raw data via API (CORS-enabled)

Research Dataset

Aggregate scan summary for independent verification: 2,170,994 packages across 11 ecosystems, collected August 3, 2026. Per-package rows are not included.

This archive carries known errors

Its download counts came from collectors that recorded a failed request as a count of zero, so they are understated, and the Hex and pub.dev scans behind its package totals were both defective. Every affected field is listed in the file's corrections block, with the direction of each error. The package-level corpus figures are unaffected. For current measured figures use the JSON or HTML report above.

Find Weak Crypto in Your Code

CryptoServe scans your codebase for vulnerable cryptographic implementations and generates a migration plan

Scan your project for weak cryptography
Generate a Cryptographic Bill of Materials
Run the global crypto adoption census

View on GitHub