The artifact is substantial and includes a README, changelog, and no install-time scripts. Its organization-backed repository is not archived, but the project has little visible adoption and lacks a security policy.
45%
Total Score
100
100
64
83
This is the package's only release, published in June 2018, with no releases in the last 12 months; the long period without updates raises abandonment and compatibility risk.
The manifest declares MIT, while the bundled license file is recognized as GPL-3.0. That unresolved mismatch creates a material legal and dependency-adoption concern.
The repository name does not match the package name, and no package-name mention was found in the README. Although this can occur with subpackages, the available evidence does not establish a clear package-to-repository relationship.
The repository has 0 stars and 0 forks, with only 2 watchers. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of community review or continued use.
The linked repository has no security policy. This is a transparency gap for a payment-related plugin, although it is not evidence of a security defect by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.