The package includes tests, a usable README, stable versioning, and only two runtime dependencies. Its missing license and absent activity since 2019 make long-term maintenance and legal adoption uncertain.
42%
Total Score
0
100
70
83
The package has had 3 releases, all concentrated on 31 July 2019, with no releases in the last 12 months and a package age of 2,608 days. This strongly indicates abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap. No provided maintenance signal compensates for this inactivity.
Neither the registry metadata nor the package or repository contains a recognized license declaration or license file. The README mentions MIT, but that is not a formal detected license artifact in this signal.
The repository has no security policy and no security scanning tools. For a cryptographic key-derivation library, this reduces transparency around vulnerability reporting and review.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
simplito/elliptic-php Version ^1.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.