The package includes tests, a clear README, and an MIT license. Its matching repository and Composer build setup improve transparency, but the project offers limited security-process evidence.
56%
Total Score
50
83
100
Only two releases exist, both published within about 15 hours, followed by more than a year without a new release. That weakens evidence of ongoing maintenance.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and raising abandonment concern.
The repository has 0 stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but there is no visible community signal to offset the weak activity record.
Composer is used for the build, which is appropriate, but no security-scanning tooling was detected. This is a modest transparency and maintenance-process gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.2 | — | — |
kornrunner/secp256k1 Version ^0.2 | — | — |
simplito/elliptic-php Version ^1.0 | — | — |
exorcist-guo/data-types Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.