The package includes a substantial README, tests, a stable release, and no install-time scripts. Its license files conflict with the MIT declaration, and both registry releases and repository commits have stopped for over two years.
58%
Total Score
50
70
50
The manifest declares MIT, but the artifact license file is recognised as GPL-3.0; although a license file exists, this mismatch creates real uncertainty for adopters.
The latest release was published on February 12, 2024, with no releases in the last 12 months and only three releases overall; this indicates the package may be aging, though not necessarily abandoned.
The repository has no commits and no active maintainers in the last three months, while its last push was in February 2024. This materially raises maintenance and abandonment risk.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools are present. That is a modest transparency and maintenance weakness rather than a standalone severe risk.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities in a payment-gateway library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
shrikeh/teapot Version ^1.0|^2.0 | — | — |
alcohol/iso4217 Version ^3.0|^4.0 | — | — |
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.