Package Health

byphp/tron-api

The MIT license, README, tests, source tree, and release notes make the package inspectable and easier to adopt. It has no repository security scanning, adding uncertainty when future changes arrive.

Latest 2.0.1PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

All five releases arrived within roughly 15 minutes on the first release day, and there have been no releases in the last 12 months despite the package being about 27 months old. This is strong evidence of stalled maintenance.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving little evidence of current development.

Repo popularitycaution

The repository has 0 stars and 0 forks, with only 1 watcher. Popularity is not decisive by itself, but it provides no supporting evidence of a sustained community.

Repo toolingcaution

Composer is used for builds, which fits the PHP package, but no security-scanning tools are configured. The missing scanning reduces confidence in ongoing maintenance hygiene.

Security policycaution

The repository has no security policy, so there is no documented process for reporting or coordinating security fixes. This is a transparency and maintenance gap, though not a severe risk on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Shamsudin Serderov

Direct Dependencies

DependencyLast ReleaseScore
byphp/secp256k1
Version ^1.0
fenguoz/web3.php
Version ^1.0
guzzlehttp/guzzle
Version ^7.2
fenguoz/data-types
Version ^1.0
simplito/elliptic-php
Version ^1.0

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform