Usable with caveats: it has a long release history, recent stable releases, and an organization-backed repository, but the SDK has almost no user documentation and no recent repository commits. The missing license and limited project safeguards add adoption risk.
62%
Total Score
75
75
50
No declared license or license file was found in the package or repository, leaving the legal terms for using this SDK unclear.
The package includes a GitHub release for this version, which documents the release, but its README contains only 11 characters and the repository has no tests or changelog. The minimal README is a meaningful problem for consumers integrating an SDK, while the absent packaged tests and changelog are normal artifact packaging practice.
The repository recorded no commits and no active maintainers during the last 3 months, which conflicts with the recent registry release history and raises concern about current maintenance capacity.
The repository has zero stars and zero forks, providing little independent evidence of adoption or community support; this is supporting caution rather than a decisive failure.
Composer is used for builds, but no security scanning tool is configured. That limits automated safeguards for a payment-related SDK, although it is not evidence of a direct defect.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.6 | — | — |
php-http/message Version ^1.8 | — | — |
jane-php/open-api-runtime Version 4.4.0 | — | — |
jane-php/json-schema-runtime Version 4.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.