The MIT licensing, organization-owned repository, and two runtime dependencies provide a clear foundation. Documentation and security-process coverage are thin, so pin version 1.0.0 and expect limited maintenance resilience.
58%
Total Score
67
100
79
50
The artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the absence of consumer documentation is a minor transparency gap for a payment plugin.
This is a new package with one release and no established release history, so maturity and maintenance continuity cannot yet be demonstrated.
One contributor accounts for all commits in the past three months. Organization backing provides some handoff capacity, but no second active contributor is observed.
Only one commit was recorded in the past three months from one active maintainer. Because the package is newly published, this is limited evidence rather than proof of collapse, but it leaves maintenance capacity untested.
Composer is used as a build tool, which supports reproducible package handling, but no security scanning tools were detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cetera-labs/plugin-sale Version * | — | — |
retailcrm/atol-online-client Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.