The repository has a working test suite and a clear README, while the MIT license is explicit. Install-time scripts and no published security policy add modest maintenance and review overhead.
68%
Total Score
50
93
50
The package runs post-install and post-update scripts, which increase installation-time behavior and review overhead. No provided signal shows that these scripts are unsafe, so this is a moderate hygiene concern rather than a severe risk.
The repository recorded zero commits and zero active maintainers during the last three months. This weakens evidence of ongoing maintenance despite the package's frequent release history.
The repository uses Composer build tooling, but no security scanning tools were detected. For a package handling payment-terminal integrations, the missing security automation is a modest transparency and maintenance gap.
No security policy was found in the repository. This makes vulnerability reporting and disclosure expectations less clear, though it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.11.3 | — | — |
ramsey/uuid Version ^4.2 | — | — |
twbs/bootstrap Version 5.3.8 | — | — |
monolog/monolog Version ^2.11 | — | — |
symfony/serializer Version ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.