The MIT license, tests, and detailed README improve transparency. Its short history leaves little evidence of long-term maintenance, and repository security practices are limited.
68%
Total Score
50
100
83
83
The repository is owned by an individual user rather than an organization, so the small registry maintainer context is not offset by visible organizational backing.
The package is only 59 days old, with four releases concentrated over roughly one day, so it has limited evidence of sustained maintenance beyond its initial launch.
The repository has no open issues or pull requests and no issue or pull-request activity in the last month. Because the project is only 59 days old, this is limited evidence rather than proof of abandonment.
The repository has zero stars, forks, and watchers, providing no external adoption evidence. Popularity is supporting evidence, so this modestly reduces confidence rather than determining the verdict.
The repository uses Composer build tooling, but no security scanning tool was detected, leaving a meaningful security-maintenance gap for a payment integration.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
magento/module-quote Version * | — | — |
magento/module-sales Version * | — | — |
magento/module-store Version * | — | — |
magento/module-vault Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.