The package is small, clearly licensed, and includes a release note for this version. Its repository has no security tooling or policy, and does not clearly identify the package in its README. Pinning this version should be treated as a maintenance risk.
45%
Total Score
50
69
50
The package has had no release in about five years, after only three releases in total. That long silence is strong evidence of abandonment risk, although the stable 1.0.2 version may indicate a small, finished package.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. No provided activity signal compensates for this lack of recent maintenance.
The linked repository neither matches the package name exactly nor mentions the package in its README, so ownership of this package is less transparent than expected. Organization backing partly reduces that concern but does not remove it.
The repository has zero stars, forks, and watchers, providing no community evidence to offset the absence of recent maintainer activity. Popularity is only supporting evidence, so this is a secondary concern.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest hygiene concern rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
simplito/bn-php Version ~1.1.0 | — | — |
brtnetwork/buffer Version v1.0.0 | — | — |
simplito/elliptic-php Version ^1.0 | — | — |
brtnetwork/brt-address-codec Version v1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.