The package has a clear MIT license, tests, documentation, and a matching source repository. Its small dependency base and clean workflow audit help, but the project shows little evidence of current maintenance or security oversight.
38%
Total Score
50
100
78
75
The repository is owned by an individual account rather than an organization, so there is no provided evidence of institutional backing. This is relevant context but not independently decisive.
The package has had only two releases, with none in the last 12 months; its latest release was over three years ago. This is strong evidence of stagnation for a library that integrates with a changing blockchain ecosystem.
There were zero commits and zero active maintainers in the last three months, consistent with the release history showing prolonged inactivity. This materially raises abandonment risk.
The repository reports zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no external adoption signal to offset the maintenance concerns.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance weakness, not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3|^7.0 | — | — |
kornrunner/keccak Version ~1.0 | — | — |
phpseclib/phpseclib Version ~2.0.30 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.