The package includes tests, a changelog, and a clear MIT license. Its single maintainer, absent security policy, and minimal repository activity leave little evidence of ongoing support.
42%
Total Score
50
100
63
75
Only two releases were published, both in August 2019, with no releases in the last seven years. This is strong evidence of abandonment for a payment integration package.
Only one registry maintainer is listed, and project_backing identifies an individual-owned repository rather than organizational backing. That leaves limited visible continuity if the maintainer stops supporting it.
The repository is owned by an individual account rather than an organization. Individual ownership is not inherently unsafe, but it provides less visible continuity when combined with the long maintenance gap.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is consistent with a dormant project, though it is weaker evidence than the release history.
The repository has one star, zero forks, and one watcher. Popularity is only supporting evidence, but these counts provide little external adoption or review signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
stripe/stripe-php Version ^6.40 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.