The package includes a clear README, MIT licensing, repository tests, and no install-time scripts. Its small contributor base, missing security policy, and unpinned workflow actions warrant routine caution.
82%
Total Score
67
100
100
75
The repository is owned by a user rather than an organization, so the single-person ownership context provides limited formal handoff capacity; recent commits partly compensate for that limitation.
Commit activity is concentrated in one human contributor, who made about 85% of recent commits; the second contributor is a release bot, leaving limited demonstrated human redundancy.
The repository has no security policy. This is a transparency gap for a payment API SDK, although the available tooling and active maintenance provide some compensating evidence.
Both workflows were fully analyzed with no untrusted checkouts, script injection, or audit findings. However, all 10 action references are unpinned and one release workflow grants top-level write permissions, creating a moderate workflow-hygiene concern without an observed dangerous trigger or sink.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.