The MIT license, readable documentation, and matching source repository make the package straightforward to inspect. Its small project footprint, absent tests, and lack of security tooling leave little evidence of ongoing support.
35%
Total Score
50
75
50
The package has only one release, published over 8 years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a payment integration library.
Only one registry account has publish access. The linked repository is user-owned rather than organization-backed, so this provides limited evidence of maintainer depth.
Composer is used for builds, but no security-scanning tools are present. For a payment-related integration, that is a meaningful hygiene gap, though it is not proof of unsafe code.
The repository is not archived, but it was last pushed on January 9, 2018, which reinforces the release-history concern rather than showing active maintenance.
The repository has no security policy. This weakens vulnerability-reporting transparency for a package handling payment integration, especially given the absence of recent maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.3 | — | — |
laravel/framework Version 5.5.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.