The bundle has a clear README and a small dependency surface. Its source has had no commits or releases since December 2016 and provides no tests or security policy, making maintenance risk high.
40%
Total Score
0
50
50
The package has had no releases in the last 12 months, and its latest release was in December 2016 despite being over 10 years old. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and indicating no current maintenance capacity.
Composer build tooling is present, but no security-scanning tools were detected. That weakens ongoing assurance, although it does not outweigh the more serious maintenance evidence by itself.
The repository has no security policy, leaving users without a documented reporting path. For a payment integration, this is a meaningful transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.