The compact package is clearly licensed and has a matching organization-owned repository, but consumer-facing safeguards are thin. Its early-stage version, absent tests, and long pause in development make long-term support uncertain.
44%
Total Score
75
100
75
75
The latest release was in February 2024, with no releases in roughly two and a half years and none in the last 12 months. This is a substantial maintenance concern despite six releases in the package's early history.
The repository had zero commits and zero active maintainers in the last three months, consistent with a project that has been inactive since February 2024. This materially increases abandonment risk.
The repository has zero stars and forks and one watcher, so there is little public adoption evidence to support confidence in continued maintenance. Popularity is only supporting evidence, but it does not compensate for the inactive project.
Composer is used for the build, but no security-scanning tools are present. For a package handling wallets, keypairs, and passphrases, the absence of visible security scanning is a meaningful hygiene gap.
The repository has no security policy. That weakens disclosure transparency for a package handling wallet and cryptographic data, though it is not by itself evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
furqansiddiqui/bip39-mnemonic-php Version ^0.1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.