It has a clear MIT license, tests, release notes, matching repository, and a small dependency set. The project is not archived or deprecated, but its repository has had no commits or releases since October 2019 and lacks a security policy.
57%
Total Score
50
100
78
88
Only one release exists, published in October 2019, with no releases in the last 12 months; this indicates substantial abandonment risk for a payment integration.
There were zero commits and zero active maintainers in the last three months, consistent with the repository's last activity in 2019 and a serious abandonment concern.
There are no open issues or pull requests and no recent activity; this is consistent with a small inactive project, but it offers no evidence of ongoing support.
The repository has only 2 stars and 1 fork, so there is little external adoption evidence; popularity is supporting evidence and does not independently make the package unsafe.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanning is a hygiene gap rather than evidence of a specific vulnerability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
omnipay/common Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.