Payum Stripe gateways bundle
68%
Total Score
75
100
88
100
The package has existed for about 6 years with 10 releases, but only one release in the last 12 months; this suggests slower maintenance rather than abandonment on its own.
There were zero commits and zero active maintainers in the last 3 months. The recent release and repository push provide some counterevidence, but ongoing development capacity still appears thin.
Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency and hygiene gap rather than a dependency-blocking risk.
All 3 workflow action references are unpinned, weakening build reproducibility. The reported cache-poisoning issue has low confidence and is hygiene at most; the audit otherwise analyzed the single workflow completely.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^6.4 | ^7.2 | ^8.0 | — | — |
payum/payum-bundle Version ^2.4 | — | — |
symfony/http-kernel Version ^6.4 | ^7.2 | ^8.0 | — | — |
flux-se/payum-stripe Version ^2.0 | — | — |
symfony/dependency-injection Version ^6.4 | ^7.2 | ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.