The artifact is small and documented, with no install scripts or dependency sprawl. Its organization-backed repository matches the package and provides provenance, but it has no tests or security tooling to support a payment integration.
15%
Total Score
0
50
50
The README explicitly says the payment validation methods are not safe and advises against using the library for webshops. Although the package includes documentation, that warning is a severe concern for a payment adapter.
The latest release was published in February 2015, with no releases in the last 12 months and only four releases overall. This indicates the package has been inactive for more than 11 years.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing long-term abandonment.
Composer is used for builds, but no security scanning tools are present. That is a meaningful hygiene gap for a package handling payment flows.
The repository has no security policy, leaving no documented reporting or response process for vulnerabilities in this payment integration.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
omnipay/common Version ~2.3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.