Nostr NIP-01 implementation in PHP
74%
Total Score
caution
Usable with caveats: maintenance is active, but all recent commits come from one contributor.
All four commits in the last three months came from one contributor, leaving maintenance dependent on a single active person. Organization ownership provides some backing, but no second recent contributor is shown.
Composer is used for builds, but no security-scanning tool is reported. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, so users are not given a documented channel or process for reporting vulnerabilities.
The only workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. Its single action use is unpinned, which is a supply-chain hygiene gap, while the absence of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nostriphant/secp256k1 Version ^0.1.0 | — | — |
nostriphant/functional Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.