The repository includes tests, release notes, and clear organization backing. Its licensing and package identity are transparent, but the maintenance cadence and workflow hygiene warrant caution for long-lived dependencies.
62%
Total Score
75
88
50
The package defines post-install and post-update Composer scripts. Install-time scripts expand dependency-install behavior and deserve caution even though this signal does not show that they are malicious.
The package has only 3 releases since February 2020, with no releases in the last 12 months and a median interval of about 901 days. This indicates a slow maintenance cadence, though the latest release is established rather than abandoned outright.
There were 0 commits and 0 active maintainers in the last 3 months. Although the repository is not archived, the observed recent development activity is currently paused.
The project uses Make and Composer build tooling, but no security-scanning tool was detected. For a small contracts package this is a modest transparency gap rather than a severe risk.
The repository has no security policy. That weakens the project's documented vulnerability-reporting process, though it does not by itself show unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wyrihaximus/pool-info Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.