Organization backing, tests, a substantial README, and a matching repository provide useful support. The workflow has all seven actions unpinned, and the repository lacks a security policy and security scanning.
70%
Total Score
88
50
88
50
Nine runtime dependencies, including cryptographic and HTTP libraries, create a meaningful dependency surface but are reasonable for this SDK's stated functionality.
One contributor made all 11 commits in the last 3 months, leaving maintenance highly concentrated and increasing continuity risk.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-process gap for an SDK handling payments and transaction signing.
The repository has no security policy, which reduces transparency for reporting vulnerabilities in a package handling payments, wallets, and transaction signing.
v0.12.0 is not a stable major release, so API stability may be less certain, although it is not a prerelease and recent releases are consistent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.5 | — | — |
kornrunner/keccak Version ^1.1 | — | — |
olifanton/interop Version ^1.4 | — | — |
phpseclib/phpseclib Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.