The package includes a README, tests, a declared MIT license, and no install-time scripts. Its recent release activity is encouraging, but no security policy, zero repository engagement, and one active contributor limit confidence in long-term maintenance.
65%
Total Score
50
100
88
83
One contributor performed all commits in the last three months, creating a high concentration risk. The repository is user-owned rather than organization-owned, so no organizational handoff is shown to compensate for it.
Only one commit was recorded in the last three months, from one active maintainer. The recent push is positive, but the very small activity sample gives limited evidence of sustained maintenance.
There are no open issues or pull requests and no recent issue or pull-request activity. This is not proof of neglect, but it leaves little evidence of community review or support.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of any external adoption provides little independent validation for this young package.
Composer is used for builds, which fits the ecosystem, but no security scanning tooling was detected. That is a meaningful transparency gap for a payment SDK, though it is not severe on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.