The package has useful consumer documentation, tests, a changelog, and a matching source repository. Its short release history, absent security policy, and unpinned workflow actions leave modest maintenance and build-integrity concerns.
78%
Total Score
100
100
88
75
The package is only 71 days old and has two releases, both published within about an hour, so long-term maintenance and release discipline remain unproven. Recent repository activity partly offsets its limited history.
Composer build tooling is present, but no security-scanning tool is reported, leaving a modest repository-hygiene gap.
The repository has no security policy, making vulnerability reporting and coordinated disclosure less clear for a payment SDK.
The single workflow was fully analyzed without dangerous triggers or audit findings, but both of its action references are unpinned, which weakens build reproducibility and action supply-chain integrity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.