The package is clearly documented, lightweight, licensed, and has no install-time scripts. Its recent activity is encouraging, but the project is still young, all recent commits come from one contributor, and no security policy or scanning is present.
68%
Total Score
67
100
88
83
The repository is owned by an individual user rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.
The package is only 46 days old with two releases, including one 14-day release interval; this shows initial activity but not a long maintenance record.
One contributor made all seven recent commits, leaving maintenance highly dependent on a single person.
Composer is used for builds, but no security scanning tooling was detected, leaving a modest security-process gap.
The repository has no security policy, which weakens vulnerability-reporting transparency for an SDK handling payment-gateway integrations.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.