The focused package has one runtime dependency, tests, a clear MIT license, and an organization-backed matching repository. However, the long maintenance gap leaves compatibility and abandonment concerns for a payment integration.
57%
Total Score
50
100
86
50
The latest release was published in December 2020, with no releases in the last 12 months. That long gap is a meaningful maintenance and compatibility concern, although the package has a stable release history and is not deprecated.
There were no commits or active maintainers in the last three months, consistent with the release gap. This indicates a real risk that compatibility fixes may not arrive promptly.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy. For a payment integration, that reduces transparency around reporting and handling vulnerabilities, though it does not by itself show an active security problem.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
omnipay/common Version ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.