The small codebase has tests, a clear README, and a matching source repository. Its long release gap and nearly six years without recent commits leave maintenance uncertain, while the missing security policy adds a smaller concern.
54%
Total Score
33
100
81
50
The latest release was in November 2014, with no releases in the past 12 months, indicating a very long period without published updates. The stable version and release history show this is not a prerelease project, but they do not offset the age of the release.
There were no commits and no active maintainers in the past three months, and the last recorded repository push was nearly six years ago. This is strong evidence of stalled maintenance for a payment integration.
The repository is owned by an individual user rather than an organization, so the single registry maintainer is consistent with the available project backing. There is no organizational support signal to offset the stale activity.
There were no new or closed issues or pull requests in the past month, while three issues and two pull requests remain open. This suggests limited current project attention, though the small project size makes the signal less decisive than the release gap.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning coverage is a modest repository-hygiene concern rather than evidence that the package is unsafe to depend on.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
omnipay/common Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.