The MIT license, clear README, repository tests, and lack of install-time scripts improve transparency and adoption. The small organization-backed project has no recent activity, no security policy, and workflow references that are all unpinned and include archived actions.
45%
Total Score
50
67
75
The latest release was in January 2023, with no releases in the last 12 months. That long publication gap materially raises abandonment risk despite the nine-release history.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the last push being in January 2023, this is strong evidence that maintenance has stopped.
The linked repository is not archived, which preserves a path for maintenance, but it was last pushed in January 2023 and therefore does not offset the broader inactivity evidence.
The repository has no security policy. For an extension handling wallet authentication and signatures, that leaves vulnerability-reporting practices unclear.
v0.1.8 is not a prerelease, but the package remains below major version 1, so its maturity signal is limited. This is a modest concern alongside the long maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^1.5.0 | — | — |
sijad/laravel-ecrecover Version ^0.0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.