The package has clear installation documentation, a changelog, a stable release line, and no install-time scripts. Treat it as a maintenance risk for long-lived Magento deployments.
62%
Total Score
67
88
83
The artifact includes a license file and the repository also has one, but the detected Apache-2.0 license does not match the manifest declaration of OSL-3.0 and AFL-3.0. The mismatch warrants checking the intended licensing before adoption.
One contributor made all commits in the last 3 months, concentrating recent maintenance in a single person. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Only 1 commit was recorded in the last 3 months, indicating limited recent development activity. The recent package release partly offsets this, but the low repository activity remains a maintenance concern.
Composer is used for builds, but no security-scanning tooling is reported. For a payment integration, the absence of visible automated security checks is a meaningful hygiene gap.
The repository has no security policy. That reduces transparency about how vulnerabilities in this payment module should be reported and handled.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.