Documentation, tests, licensing, and a clean install profile provide useful safeguards. Its cryptography-focused code has seen no maintenance for nearly seven years, with no security policy and negligible repository adoption.
43%
Total Score
0
79
83
The latest release was nearly seven years ago, with no releases in the last 12 months despite 73 historical releases. This strongly raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and lack of current maintenance evidence.
The repository has zero stars, forks, and watchers, providing no meaningful community adoption or external visibility to compensate for the inactivity.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a cryptography-focused library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mdanter/ecc Version ^0.4.0 | — | — |
composer/semver Version ^1.4.0 | — | — |
bitwasp/buffertools Version ^0.4.0 | — | — |
lastguest/murmurhash Version v1.3.0 | — | — |
pleonasm/merkle-tree Version 1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.