The repository has no commits in the last three months and no active maintainers, with no security policy or tests. It has a stable release and a small dependency surface, but those do not offset the maintenance warning.
18%
Total Score
50
100
75
75
Packagist marks the entire package as abandoned and names pmgw/payment-gateway-php-sdk as its replacement. This is a direct warning against starting a new dependency on this package.
The repository recorded zero commits and zero active maintainers in the last three months. This provides concrete evidence of no current maintenance capacity.
The package has 55 releases and a long history, but it had no releases in the last 12 months and its latest release was 3.21.1 on July 2, 2024. That indicates release activity has stopped.
The repository uses Composer for builds, which fits the package ecosystem. No security scanning tools were detected, a minor hygiene gap that adds to the overall concern.
The linked repository has no security policy, leaving no documented process for reporting or handling security issues. This compounds the maintenance concerns for a payment gateway library.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.