Usable with caveats: the package is a small, licensed, stable API with matching organization backing and a documented 1.0.7 release. However, it has had no registry releases in about 20 months and no repository commits in the last 3 months, so ongoing maintenance is uncertain.
58%
Total Score
50
100
83
88
The repository recorded zero commits and zero active maintainers in the last 3 months. Combined with no registry releases in about 20 months, this is the strongest evidence that maintenance may have stalled.
There have been no releases in about 20 months, despite seven releases overall. This is a meaningful maintenance concern, although the package had an initial release history rather than being entirely unproven.
There are no open issues and three open pull requests, but none were merged or newly opened in the last month. The untouched pull requests add a modest concern about responsiveness.
The repository has one star and two forks, indicating limited adoption and external review. Low popularity is supporting evidence rather than a decisive problem, especially for a small organization-backed package.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a transparency and maintenance gap, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
simplito/elliptic-php Version ^1.0.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.