Recent releases and an active organization-owned repository provide useful maintenance evidence. The README is clear, but there is no security policy and ongoing work is concentrated in one contributor, so long-term continuity is less certain.
68%
Total Score
67
100
88
50
The manifest declares a proprietary license, so the release is licensed but may impose meaningful usage restrictions for dependent projects. No license file was detected to clarify those terms.
All recent commit activity comes from one contributor, creating continuity risk if that person becomes unavailable. Organization ownership provides some handoff capacity, but no second active contributor is shown.
One commit was recorded in the last 3 months, showing some current activity but a limited maintenance pace.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools are reported. The missing scanning is a modest hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a payment gateway.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
duitkupg/duitku-php Version dev-master | — | — |
blesta/composer-installer Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.