The package has a very small README and no security policy, while its simple dependency profile and organization-owned repository provide limited reassurance. Pin this version only if you can accept that maintenance appears to have ended.
40%
Total Score
50
100
60
50
The latest release was over 8 years ago, with zero releases in the last 12 months; this is strong evidence that the package is no longer maintained.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and raising abandonment risk.
The package includes a README, but it is only 8 characters long and provides almost no consumer guidance. Missing tests and a changelog are normal for a published artifact and are not gaps by themselves.
Composer build tooling is present, but no security-scanning tooling was detected; this is a minor transparency and maintenance concern alongside the project's inactivity.
The linked repository has no security policy, reducing transparency about how vulnerabilities should be reported for a package that handles payment functionality.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kazist/payments Version @stable | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.