The clear README and matching MIT license improve transparency, while the small project footprint limits confidence in ongoing support. Pinning this release would leave you on an unmaintained beta-era integration.
35%
Total Score
0
67
50
This package has only one release, published about 9 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk.
The repository has had zero commits and zero active maintainers in the last 3 months, consistent with a project that has not been maintained for years.
Composer is used for builds, but no security scanning tooling is present. This is a modest transparency and maintenance concern, not evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting expectations unclear. This is secondary to the much stronger abandonment signals.
The latest version is v0.1 rather than a stable major release, which adds maturity risk alongside the stale release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
payum/payum Version ^1.3 | — | — |
sylius/sylius Version ^1.0@beta | — | — |
symfony/symfony Version ^3.2 | — | — |
payum/payum-bundle Version ^2.1 | — | — |
mollie/mollie-api-php Version ~1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.