The MIT license, matching repository, README, and small dependency set make the package transparent enough to inspect. Its cryptographic code lacks recent maintenance evidence and repository security tooling; pin this version only after a focused code review.
38%
Total Score
0
100
79
88
The package has had only one release, published 487 days ago, with no releases in the last 12 months. That provides little evidence of ongoing maintenance or release responsiveness.
The repository shows zero commits and zero active maintainers in the last three months, while its last push was nearly five years ago. This is strong evidence that maintenance has stalled.
Composer is used for builds, but no security-scanning tools are present. For a package handling hierarchical cryptographic keys, this weakens ongoing validation and transparency.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a meaningful transparency gap for security-sensitive code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jundayw/bip32-sdk-php Version ^1.0 | — | — |
simplito/elliptic-php Version 1.0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.