It has a clear GPL license, a usable README, and a recent release note. The small maintenance footprint and unpinned deployment actions warrant pinning the version and checking updates.
76%
Total Score
67
100
100
75
One contributor made all commits in the last 3 months, concentrating the observed maintenance capacity in a single person. The repository is user-owned rather than organization-owned, so there is no provided organizational backing to offset that concentration.
Only 1 commit was recorded in the last 3 months, showing recent activity but a thin maintenance cadence for a payment integration.
The repository has no security policy. That is a transparency gap for a payment gateway, where a documented vulnerability-reporting path would be valuable.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings, and it avoids top-level write permissions. However, both action references are unpinned, leaving the deployment workflow exposed to changes in referenced action versions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
maib/maibapi Version ^3.0 | — | — |
monolog/monolog Version ^2.7 | — | — |
automattic/jetpack-autoloader Version ^5.0 | — | — |
alexminza/wc-payment-gateway-base Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.