The MIT license, clear README, and release notes make the package easier to adopt. Its four runtime dependencies are modest, but it has no security policy or automated security scanning.
61%
Total Score
50
100
83
75
The repository is owned by an individual rather than an organization, so the short maintainer structure offers no visible organizational backing to offset the inactive commit history.
The package has only two releases, both published in June 2025, and none in the last 12 months. This limited history and long pause reduce confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, following a last push in June 2025. This is direct evidence that maintenance has stalled.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no community signal to compensate for the lack of recent maintenance.
Composer build tooling is present, but no security scanning tools were detected. That weakens repository hygiene for a payment-integration library.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.