Clear licensing, tests, and a usable README reduce adoption friction. The small dependency surface and matching source repository improve transparency, but the project has not shown recent development activity.
63%
Total Score
50
100
78
88
The repository is owned by a user account rather than an organization, so there is no visible organizational backing to offset the small maintainer base.
All five releases arrived within roughly four days, and no later release is shown despite the package being about nine months old. This brief burst followed by a long release gap lowers confidence in ongoing maintenance.
There were zero commits and zero active maintainers in the last three months. For a blockchain client library, that is a meaningful sign of stalled maintenance.
The repository has zero stars, forks, and watchers. This provides no supporting adoption evidence, but popularity is only supporting evidence and does not independently make the package unsafe to depend on.
Composer build tooling is present, but no security-scanning tools are reported. This is a transparency and hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ionux/phactor Version 1.0.8 | — | — |
fptron/tron-api Version ^0.0.1 | — | — |
kornrunner/keccak Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.