PHP SDK for processing payments with Global Payments, including Heartland Payment Systems and Realex Payments
68%
Total Score
caution
Usable with caveats: all recent repository commits come from one contributor.
The artifact and repository both contain a license, but the detected GPL-2.0 text is narrower than the manifest's GPL-2.0-or-later declaration, creating a compatibility and review concern.
Only one contributor made commits in the last three months, with a 100% share, leaving the project exposed to a single-maintainer continuity risk.
The repository recorded 11 commits in the last three months, so development has not stopped, but all activity is concentrated in one active maintainer.
The repository has 37 open issues and 11 open pull requests, but no new or closed issues and no merged pull requests in the last month, indicating quiet maintenance channels.
Composer is used for builds, but no security-scanning tools were detected, leaving a repository hygiene gap for a payment-focused SDK.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-11082 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. globalpayments/php-sdk is vulnerable to Cross-Site Scripting (XSS) in versions 14.1.3 - 14.1.15. | 14.1.3 - 14.1.15 | Low |
AIKIDO-2026-10497 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. globalpayments/php-sdk is vulnerable to Cross-site Scripting (XSS) in versions 14.1.3 - 14.1.8. | 14.1.3 - 14.1.8 | Low |
AIKIDO-2026-10134 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. globalpayments/php-sdk is vulnerable to Cross-site Scripting (XSS) in versions 2.2.13 - 14.1.0. | 2.2.13 - 14.1.0 | Low |
AIKIDO-2025-10693 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. globalpayments/php-sdk is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 1.2.2 - 13.3.6. | 1.2.2 - 13.3.6 | Medium |
AIKIDO-2025-10519 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. globalpayments/php-sdk is vulnerable to Insertion of Sensitive Information into Log File in versions 1.0.0 - 13.3.2. | 1.0.0 - 13.3.2 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.