The package is clearly documented, tested, licensed, and tied to a matching repository. Its two releases arrived within minutes, so maintenance over time is not yet demonstrated; the workflow also uses two unpinned actions.
68%
Total Score
67
100
94
75
The package is maintained under a user-owned repository rather than an organization, so the small apparent ownership base provides limited backing evidence.
This is a brand-new package with two releases in the same day and a median interval of about 12 minutes, so long-term maintenance is not yet established.
No commits or active maintainers were recorded in the last three months, but this repository is newly created, so the result mainly shows that a longer maintenance history is unavailable.
No security policy is present, which is a modest transparency gap for a package handling payment integrations.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. Both action references are unpinned, which weakens build reproducibility but is not a severe risk on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0|^2.0 | — | — |
korozcolt/payments-core Version ^1.0 | — | — |
psr/http-server-handler Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.