The repository has had no commits for nearly 10 years, and the package has not released in that time. It remains licensed and documented, but the beta release status and absent security policy add uncertainty for a payment integration.
32%
Total Score
0
100
70
75
The package is nearly 10 years old but has had no release in that period: its latest release was in December 2016, with zero releases in the last 12 months. This is strong evidence of abandonment for a payment library.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no update since December 2016.
The repository has no security policy. That is a transparency and response gap for a package handling payment-related integration, although the long maintenance gap is the more serious concern.
The assessed release is still a prerelease, and all recent releases are prereleases. Combined with the long period without updates, this indicates the project never reached a maintained stable release.
No GitHub Actions workflows were present, so the audit found no workflow risks; this also means there is no automated workflow evidence supporting current maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.