The project is brand new, with only two releases and no established maintenance history. It has a useful README and a clear MIT declaration, but one maintainer, no tests, and no security policy leave limited evidence for long-term support.
62%
Total Score
50
50
83
50
Seven runtime requirements, including PHP extensions and two cryptographic libraries, are a meaningful dependency surface for an SDK but are consistent with its signing and HTTP functionality.
Only one registry publishing account is listed, and the project backing is a personal account rather than an organization, leaving limited visible publishing redundancy.
The package is less than one day old and has only two releases, so there is not yet enough release history to demonstrate sustained maintenance or maturity.
The repository has zero stars, forks, and watchers. Given that the project is less than one day old, this is weak supporting evidence rather than a standalone abandonment concern.
Composer build tooling is present, but no security scanning tool was detected. For an SDK handling signing and keys, the missing security automation is a real hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lpilp/guomi Version ^1.0 | — | — |
fgrosse/phpasn1 Version ^2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.