The package is small and clearly documented, but it has little evidence of ongoing quality or security maintenance. Its organization backing and stable release reduce uncertainty, yet adopting it leaves you responsible for validating compatibility and payment behavior.
42%
Total Score
50
67
75
Only two releases exist, and none were published in the last 12 months; the latest release was in December 2021, nearly five years ago. This is strong evidence of an aging project, though the stable major version partly reduces churn risk.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the old last push, this indicates a substantial abandonment risk.
One registry account has publish access, creating a thin publishing base. The organization-owned repository provides some backing, so this is a caution rather than a severe concern.
The artifact and repository each contain only four files, including a README, manifest, and single source file. This is coherent for a narrow integration package but offers little project evidence beyond the implementation itself.
The published artifact includes a substantial README, which helps consumers integrate the payment client; absent tests and a changelog are normal for a small published PHP artifact. The repository also has no tests or changelog to strengthen maintenance transparency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.