The README, tests, release notes, organization backing, and static analysis make the project reasonably transparent. Maintenance has slowed recently, and the workflow audit found an unpinned container image while leaving one workflow unanalyzed.
65%
Total Score
67
100
100
67
No commits or active maintainers were recorded in the last three months. The recent release partly offsets this, but the lack of current development activity raises maintenance risk.
There were no new or closed issues or pull requests in the last month, despite nine open issues and two open pull requests; this supports the concern about currently limited activity.
The repository has no security policy. For an API client handling payment-related integrations, this is a transparency gap, although available Psalm scanning provides some compensating hygiene.
The audit analyzed only two of three workflows and one file failed analysis. It also found a high-confidence unpinned container image and all four action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.