The package includes a clear README, repository tests, and an MIT license. Six unpinned workflow actions and limited repository activity provide little reassurance for a payment integration.
38%
Total Score
50
79
67
The package has had no releases in the last 12 months, and its latest recorded release was over five years ago. This is strong evidence of abandonment for a payment library.
There were no commits and no active maintainers in the last three months, consistent with the package having received no releases for over five years.
The repository name does not match the package name and its README does not mention the package, so the link does not clearly establish that this repository publishes this package.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear for a payment-related library.
The release is presented as v3.0.0, while the registry reports v1.3.6.2 as the latest version, creating a material consistency concern about release metadata.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
php-di/php-di Version ~6.3.0 | — | — |
psr/container Version ^1.1 | ^2.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.