The Apache-2.0 license, matching license file, README, and no install scripts make the package transparent and straightforward to inspect. Its small dependency footprint helps, but there is no security policy or scanning. Treat it as legacy code and validate its Cielo integration before adoption.
42%
Total Score
0
100
71
75
The package has only one release, published over 9 years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a payment API client.
The repository recorded zero commits and zero active maintainers in the last 3 months. With the last push over 7 years ago, current maintenance capacity appears absent.
Composer is used for builds, but the repository has no security scanning tools. That is a hygiene gap for a package handling payment integrations, though it is not evidence of malicious behavior.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities in a payment-related client.
Version 0.1.0 is not a stable major release, and the package has never progressed beyond it. Combined with the long release gap, this reinforces its immature status.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
developercielo/api-3.0-php Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.