The package has tests, release notes, a substantial README, and matching MIT licensing. Its install hook, absent security policy, and inactive repository increase maintenance and review risk for a payment API client.
58%
Total Score
50
100
92
50
The package runs a post-install command, adding code execution during installation. No provided signal shows that this hook is harmful, so this is a review concern rather than a severe finding.
There have been no releases in the last 12 months, and the latest release was about two years ago. The 23-release history shows prior activity but does not offset the current pause.
The repository recorded no commits and no active maintainers in the past 3 months; its last push was about two years ago. This is meaningful abandonment risk for an API integration library.
The linked repository has no security policy. That weakens vulnerability-reporting transparency, which matters for a package handling payment-related API operations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gree/jose Version ^2.2.1 | — | — |
guzzlehttp/guzzle Version ^7.2 | — | — |
phpseclib/phpseclib Version ^2.0.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.