The repository includes tests, a changelog, a license, and a security policy, which improves transparency. CI uses read-only permissions, but both referenced actions are unpinned.
68%
Total Score
50
100
81
83
The package was released today, with three releases in roughly five hours and no longer-term maintenance history. This supports active initial development but leaves abandonment and maturity unproven.
One contributor made all three recent commits, giving the project a single-person maintenance dependency. The repository is user-owned rather than organization-owned, so there is no provided backing evidence to offset that concentration.
The repository has three commits in the last three months, all during this newly created release period, so it shows activity but not sustained maintenance yet.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency gap for a payment API SDK, though other repository hygiene signals provide some compensation.
Version 0.2.1 is not a stable major release, and the package describes its public API as subject to change before the first stable release. Consumers should expect compatibility changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.