The package is licensed, tested, documented, and has no install-time scripts. Its sparse release cadence and no commits in the last three months reduce maintenance confidence, while all eight workflow actions are unpinned. The repository is active and unarchived, but it has no security policy.
67%
Total Score
50
88
75
The package has existed for about 7 years but only 4 releases, with a median interval of about 538 days; one release in the last 12 months shows some ongoing maintenance but a slow cadence.
There were zero commits and zero active maintainers in the last three months, a meaningful sign of currently low maintenance activity despite the recent push and release evidence.
Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency gap rather than a severe risk.
The repository has no security policy, leaving vulnerability-reporting expectations unclear for a package that handles address and key-related functionality.
Both workflows were fully analyzed with no trigger or injection findings, but all 8 of 8 action references are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
paragonie/ecc Version ^2 | — | — |
kornrunner/keccak Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.