The README, tests, MIT license, and matching repository make the package easy to inspect. It is newly published, and its CI uses two unpinned actions without a security policy; pin those actions before relying on automated builds.
71%
Total Score
75
94
67
The package is brand new, with only two releases published within minutes and no long-term release record. That limits evidence of maturity, though the rapid v1.0.1 follow-up is not itself a negative maintenance signal.
There were no commits in the preceding three months and no active maintainers in that window, but the repository and release were created only moments before collection, so this is an immature history rather than evidence of abandonment.
The repository has no security policy, leaving no published process for reporting or handling vulnerabilities in a payment integration package.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but both of its two action references are unpinned. That is a supply-chain hygiene gap, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.8 | — | — |
symfony/config Version ^6.4|^7.0 | — | — |
symfony/console Version ^6.4|^7.0 | — | — |
symfony/routing Version ^6.4|^7.0 | — | — |
symfony/http-client Version ^6.4|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.