The package includes tests, release notes, a clear README, security scanning, and active work from five contributors. The license mismatch and unpinned workflow actions reduce transparency and build reproducibility.
70%
Total Score
88
100
88
50
The manifest declares MIT and license files are present, but the repository license detection identifies OSL-3.0, creating a material licensing mismatch that should be resolved before adoption.
The package has 85 releases over more than eight years, but none in the last 12 months; this weakens confidence in current release maintenance despite recent repository activity.
There are no open issues and three new pull requests in the last month, but none were merged during that period; this is a minor maintenance concern alongside the active commits.
The repository has no published security policy, leaving vulnerability reporting and handling expectations unclear for a payment integration.
The single workflow was fully analyzed with no injection or high-severity findings, but all five action references are unpinned, reducing build reproducibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
bugsnag/bugsnag Version ^3.4 | — | — |
magento/framework Version 100.*|101.*|102.*|103.* | — | — |
magento/module-tax Version 100.*|101.*|102.*|103.* | — | — |
magento/module-sales Version 100.*|101.*|102.*|103.* | — | — |
magento/module-payment Version 100.*|101.*|102.*|103.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.