Clear documentation, tests, a changelog, and matching Apache-2.0 licensing improve adoption confidence. The organization backing helps offset the limited history, while missing security scanning and unpinned workflow actions leave modest hygiene concerns.
68%
Total Score
67
100
81
67
The package is only 10 days old, despite six releases in that period. The rapid recent cadence is encouraging, but there is not yet enough history to establish long-term maintenance.
One contributor made all four recent commits, creating a narrow maintenance base. Organization ownership provides some handoff capacity, so this is a caution rather than a severe abandonment risk.
Four commits were made in the last three months, showing some activity, but all activity is concentrated in the current short-lived project history.
Composer build tooling is present, but no security scanning tools were detected. The missing scanner is a modest transparency and hygiene gap.
The repository has no security policy. For an SDK handling signatures, encryption, and merchant credentials, that leaves vulnerability-reporting expectations unclear.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.