The package includes tests, a clear README, matching MIT licensing, and a small dependency footprint. Its organization-owned repository and lack of install scripts help, but the missing security policy reduces transparency.
40%
Total Score
50
100
80
75
The package has only one release, published about 11 years ago, with no releases in the last 12 months. This strongly suggests abandonment risk despite the stable 1.0.0 version.
The repository recorded zero commits and zero active maintainers in the last 3 months, and its last push was in 2015. There is no observed recent maintenance to offset the old release history.
The repository has no security policy. For a payment-processing integration, this is a transparency gap, although the old and inactive project limits the practical significance of the missing policy.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
omnipay/common Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.