Again, I find myself wondering "Why not just use OpenSSL instead?"

perhaps read any of the other comments? tldr, license and it's also terrible.

OpenSSL seems to have a less restrictive licence to me (although I suppose it is an issue if you want to directly integrate it with GPL code, but that's why it's a library), and I somehow wouldn't expect a bug of this magnitude to make it past their review.

