Clear organizational ownership and release notes provide useful context for this payment integration. The project has no commits in three months, no security policy, and all three workflow actions are unpinned.
64%
Total Score
75
88
75
The package is young, with two releases over 316 days and a median interval of about 101 days; this shows some delivery activity but limited history for judging long-term maintenance.
There were zero commits and zero active maintainers in the last three months, a meaningful warning that maintenance may have slowed after the latest release.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository hygiene gap for a payment integration.
The repository has no published security policy, making vulnerability reporting and coordinated response less transparent.
The single workflow was fully analyzed with no detected sinks or high-severity findings, but all three action references are unpinned, leaving workflow dependencies exposed to moving upstream code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
antom/magento2-core Version 1.1.0 | — | — |
antom/magento2-frontend Version 1.1.0 | — | — |
antom/magento2-adminhtml Version 1.1.0 | — | — |
antom/global-open-sdk-php Version v1.4.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.