A single registry maintainer and no security policy leave limited ongoing oversight. Repository tests and documentation help, but the very small audience and long pause after December 2020 make this a poor default for new integrations.
42%
Total Score
75
71
75
The package has had no releases in more than five years, despite 78 releases concentrated on December 15, 2020. That long gap is strong evidence of abandonment risk for a library dependency.
Only one registry account has publish access, limiting publishing continuity. The organization-backed repository partly compensates for this thin registry maintainer base, but it does not demonstrate active maintenance.
The linked repository has 1 star, 0 forks, and 0 watchers, providing little evidence of a broad user or contributor base. Low popularity is supporting evidence rather than proof of abandonment, but it reinforces the stale release history.
The repository has no security policy, leaving no documented path for reporting vulnerabilities or coordinating fixes. This is a transparency and maintenance gap for a library handling cryptographic and transaction functionality.
The release is a stable major version rather than a prerelease, which supports compatibility, but the registry reports v1.0.4 as latest while v1.0.5 is being assessed, adding uncertainty around release freshness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mdanter/ecc Version ^0.5.0 | — | — |
bitwasp/bech32 Version ^0.0.1 | — | — |
composer/semver Version ^1.4.0 | — | — |
bitwasp/buffertools Version ^0.5.0 | — | — |
lastguest/murmurhash Version v2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.