The package includes tests, a README, release notes, and a clearly matching source repository. Its licensing files include both MIT and Apache-2.0 while the manifest declares only MIT, and no security policy or scanning is present.
58%
Total Score
50
71
83
The artifact and repository contain explicit license files, but they identify both Apache-2.0 and MIT while the manifest declares only MIT, creating some licensing ambiguity.
Only two releases were published, both on the same day, with no releases in the last two and a half years. This is a substantial maintenance concern for a security-sensitive library.
There were no commits or active maintainers in the last three months. Together with the absence of recent releases, this indicates currently inactive maintenance.
Composer is used for builds, but no security scanning tools are present. That is a hygiene gap for a library handling Ethereum message verification.
The repository has no security policy, leaving disclosure and response expectations undocumented for a security-related package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.72 | — | — |
web3p/web3.php Version 0.3.2 | — | — |
kornrunner/keccak Version ^1.1 | — | — |
guzzlehttp/promises Version ^2.0 | — | — |
simplito/elliptic-php Version ^1.0.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.