Recent releases show ongoing publishing, but the repository has no commits or active maintainers in the last three months. The tiny audience, absent security policy, and lookalike identity signal add maintenance and adoption uncertainty.
60%
Total Score
63
100
85
75
Only one registry account has publish access. The linked repository is organization-owned, which makes a short registry access list less concerning, but it does not establish active maintenance by itself.
The package has low artifact overlap with digitickets/lalit, which argues against it being a copied package, but the identity signal still creates some naming and consumer-confusion risk.
There were no commits and no active maintainers in the last three months. This conflicts with the recent registry releases and therefore lowers confidence in sustained development capacity.
There are no open issues or pull requests and no recent issue or pull-request activity. This is neutral for a small stable package, but provides little evidence of active community maintenance.
The repository has 1 star, 0 forks, and 1 watcher, indicating very limited public adoption and review, although popularity alone is not decisive.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
omnipay/common Version ~2.0 | — | — |
digitickets/omnipay-abstract-voucher Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.