The package has had no new release or repository commits for over four years, with no tests or security scanning. Its MIT license, focused dependency set, and clear README provide useful transparency, but the maintenance gap is substantial.
48%
Total Score
0
100
78
88
This is the only release, published over four years ago, with no releases in the last 12 months. That long period without a new release is strong evidence of limited ongoing maintenance.
There were no commits and no active maintainers in the last three months, consistent with the release history showing no activity since 2022. This materially increases abandonment risk.
The repository has only 2 stars, 1 fork, and 1 watcher. Low popularity is supporting evidence of limited adoption, but it is not decisive by itself.
Composer build tooling is present, but no security scanning tools were detected. That is a hygiene weakness for a payment integration, though it is not severe on its own.
The repository has no security policy. For a package handling payment integration, this reduces transparency about vulnerability reporting and maintenance expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
iyzico/iyzipay-php Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.