A single unauthenticated connection gives attackers a full shell; credential theft observed in under three minutes on honeypot servers.
The latest release lives at https://pypi.org/project/slmp-connect-python/, where wheel and tarball downloads and metadata are available.