Usable with caveats: the package is actively released, stable, licensed, and backed by a matching repository, but the repository shows no commits or active maintainers in the last three months and has no security policy.
68%
Total Score
67
100
89
75
Only one account has registry publishing access, which limits publishing redundancy. However, the package is associated with a matching source repository and organization namespace, so this is a modest concern rather than evidence of abandonment.
The repository recorded zero commits and zero active maintainers during the last three months, which is a meaningful maintenance concern despite the recent registry release.
The repository has only 1 star and no forks, so there is little public adoption evidence. Low popularity is supporting context rather than a health verdict for a small SDK.
Composer build tooling is present, but no security scanning tooling was detected. This weakens development hygiene, although the absence of scanning alone does not make the release unfit to use.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented for a payment SDK.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.