The artifact has a clear README, MIT licensing, repository tests, and no install-time scripts. Its small audience, missing security policy, and loose workflow pinning offer little additional confidence for long-term adoption.
20%
Total Score
0
100
50
75
Packagist marks the entire package as abandoned, with no replacement listed. Package-wide deprecation is a severe adoption risk even though this specific release is stable.
The package has 31 releases but none in the last 12 months; the latest release was in July 2023. This indicates prolonged inactivity for a package intended to support payment integration.
The repository had zero commits and zero active maintainers in the last three months, consistent with the archived state and providing no evidence of ongoing maintenance.
The linked source repository is archived, and its last push was in December 2023. Archived source substantially raises abandonment and maintenance risk.
The repository has only 2 stars, no forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little community backing to offset the maintenance concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 | — | — |
cashier-provider/core Version ^3.0 | — | — |
cashier-provider/tinkoff-auth Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.