The package is small, has a matching repository, and uses no install-time scripts. Its lone registry maintainer, absent security scanning, and inactive project reduce confidence in long-term support.
40%
Total Score
25
70
100
The latest release was over eight years ago, and there have been no releases in the last 12 months. The earlier nine-release history shows initial activity but does not offset the prolonged inactivity.
The repository recorded no commits and no active maintainers in the last three months, consistent with the package's long release gap and raising abandonment concerns.
Only one registry account has publish access. The repository is organization-owned, which provides some project backing, but observed activity remains absent.
Composer build tooling is present, but no security scanning tools were detected. This is a meaningful transparency and maintenance gap, although it is less serious than the lack of recent development.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kazist/payments Version @stable | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.