The stable version, matching organization-owned repository, and release notes provide useful continuity. No automated security scanning or repository security policy leaves a meaningful transparency gap.
61%
Total Score
75
86
50
The package has 19 releases since June 2021, but none in the last 12 months; the latest registry release was about 17 months ago. This indicates a meaningful maintenance slowdown despite its established history.
The repository recorded zero commits and zero active maintainers in the last 3 months. This reinforces the release slowdown and raises maintenance risk for a production Magento extension.
Composer build tooling is present, but no security scanning tools were detected. This is a hygiene gap, partly offset by the organization-owned, package-matching repository.
The repository has no security policy. For an extension handling payment and fraud-related integrations, that reduces transparency about vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^102.0.0|^103.0.0 | — | — |
magento/module-sales Version ^100.0.0|^101.0.0|^102.0.0|^103.0.0 | — | — |
magento/module-store Version ^100.0.0|^101.0.0 | — | — |
magento/module-config Version ^100.0.0|^101.0.0 | — | — |
magento/module-paypal Version ^100.0.0|^101.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.