The repository includes tests, a clear README, an MIT license, and a release for this version. However, the long period without published releases or commits leaves maintenance and compatibility risk high.
38%
Total Score
25
100
79
75
The latest release was in December 2021, with no releases in the last 12 months despite the package being nearly five years old. This is strong evidence of stagnation for a payment SDK, though the eight-release history shows it was previously developed.
The repository recorded zero commits and zero active maintainers over the last three months, reinforcing the long release gap and leaving little evidence of ongoing maintenance.
The package is backed by an individual user account rather than an organization, so there is no visible organizational maintenance cushion to offset the inactive project.
Composer build tooling is present, but no security scanning tools were detected. This is a hygiene gap, not evidence of abandonment by itself.
The repository has no security policy, leaving vulnerability-reporting expectations unclear for an SDK that handles payment integrations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version 1.*|2.*|3.* | — | — |
nyholm/psr7 Version ^1.4 | — | — |
psr/http-client Version 1.* | — | — |
psr/event-dispatcher Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.