The small codebase is clearly packaged and easy to inspect, with a matching repository and permissive installation behavior. Documentation is minimal, with no tests, security scanning, or security policy; pinning this unproven integration carries maintenance risk.
46%
Total Score
0
71
75
The package has only one release, published 535 days ago, with no releases in the last 12 months. This is strong evidence of limited ongoing maintenance for a payment integration.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's single-release history. This materially raises abandonment risk.
Composer build tooling is present, showing basic project structure, but no security scanning tools were detected. That missing security hygiene adds a modest concern for a payment-related package.
The repository has no security policy. This weakens vulnerability-reporting transparency, especially for a package handling payment integrations.
Version 0.0.1 is not a stable major release, so compatibility and production readiness are less established. The exact-version release notes provide some transparency but do not offset the early version.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
omnipay/common Version ~3.0 | — | — |
guzzlehttp/guzzle Version ^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.