It includes a substantial test suite, clear README, MIT licensing, and no install scripts. GitHub Actions uses unpinned references, and the project has no security policy.
65%
Total Score
50
100
93
75
The package is 0 days old with only 2 releases, published about 2 hours apart. This is too little history to establish dependable maintenance, though it is not evidence of abandonment by itself.
There were 0 commits and 0 active maintainers in the last 3 months. Because the package itself is only 0 days old, this mainly means maintenance capacity is not yet demonstrated rather than clearly collapsed.
The repository has no security policy. That weakens the documented process for reporting vulnerabilities, which matters for a package handling payment integrations.
The single workflow was fully analyzed with no audit findings or untrusted checkouts, but both action references are unpinned. That leaves a modest reproducibility and action-supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1|^2.0|^3.0 | — | — |
psr/clock Version ^1.0 | — | — |
nesbot/carbon Version ^2.67|^3.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.