Recent releases and organization backing provide useful maintenance context. Only one contributor made the sole commit in the last three months, so future continuity is less certain.
67%
Total Score
67
93
75
The release includes an MIT license file, so it is licensed, but the manifest declares it as proprietary. That unresolved mismatch creates a real transparency and usage-risk concern.
All recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second recently active contributor is shown.
There was one commit by one active maintainer in the last three months. Recent activity exists, but the very low volume limits evidence of sustained maintenance.
The linked repository has no security policy. For a payment gateway, that is a transparency gap because it gives maintainers no documented route for reporting security issues.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
blesta/composer-installer Version ~1.0 | — | — |
gocardless/gocardless-pro Version ^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.