Risky to adopt for new payment functionality: the package has had no release or repository activity for about eight years. It is licensed, not deprecated or archived, and the organization-backed repository matches the package, but maintenance and consumer documentation are very weak.
42%
Total Score
50
72
88
The latest release was published on July 26, 2018, and there were no releases in the following 12 months; this indicates prolonged abandonment despite the package having 56 historical releases.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no maintenance for about eight years.
The artifact includes a README, but it is only 11 characters long and provides no meaningful usage guidance for a payment package. Missing tests and a changelog in the published artifact are normal packaging practice and are not concerns by themselves.
The repository has zero stars and forks and only one watcher, providing little community evidence to offset the long maintenance gap, though popularity is supporting evidence rather than a verdict.
Composer is used as the build tool, but no security scanning tools are present; this is a transparency and maintenance gap rather than evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.