Risky to adopt for a new payment integration. It has a clear, licensed package with documentation, tests, and organization backing, but only one release was published over six years ago and the repository has had no recent commits, leaving substantial abandonment risk.
46%
Total Score
50
100
72
88
The package has only one release, 1.0.0, first published over six years ago, with no releases in the last 12 months. That long period without a release is a significant maintenance concern for a payment library.
There were zero commits and zero active maintainers in the last three months. Combined with the old last push and single-release history, this is strong evidence that active maintenance has stopped.
Registry publishing access is held by one maintainer, which is a limited publishing base. The organization-owned repository provides some compensating project backing, but it does not demonstrate current maintenance activity.
The repository has 14 stars, zero forks, and one watcher. This modest adoption does not prove a problem, but it provides little external evidence of mature community support.
Composer is used as the build tool, but no security scanning tools are configured. This is a transparency and maintenance gap, though it is less significant than the absence of recent development activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.