The package is clearly licensed and documented, with repository tests and no install-time scripts. Its small user base and missing security policy add modest concerns.
43%
Total Score
50
50
85
88
Eight runtime requirements, including HTTP, event, cryptography, and support components, create ordinary maintenance exposure for a payment SDK but do not show an excessive dependency burden by themselves.
Only one registry account has publish access. That creates a thin publishing base and increases continuity risk, though it is not evidence of current inactivity on its own.
The repository is owned by a personal GitHub account rather than an organization, so there is no visible organizational backing to compensate for the single maintainer and prolonged inactivity.
The package has had no releases in the last 12 months, and its latest release was published in March 2022. That long release gap is a substantial maintenance concern for a payment SDK.
The repository had zero commits and zero active maintainers in the last three months, with the last push in March 2022. This is the strongest evidence of prolonged abandonment risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pimple/pimple Version ^3.3 | — | — |
chenpkg/support Version ^1.0 | — | — |
guzzlehttp/guzzle Version ^6.2 || ^7.0 | — | — |
symfony/http-foundation Version ^2.7 || ^3.0 || ^4.0 || ^5.0 || ^6.0 | — | — |
symfony/event-dispatcher Version ^4.3 || ^5.0 || ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.