PHP SDK for Myanmar payment gateways: KBZ Pay, Wave Money, AYA Pay, Yoma MMQR and CyberSource. Framework-agnostic, typed requests and results, works with any PSR-18 HTTP client.
62%
Total Score
caution
A one-day-old alpha release with all four workflow actions unpinned needs extra supply-chain caution.
The package is only 1 day old with four releases, so its maintenance record is too short to establish long-term reliability. Rapid early releases provide some evidence of active development but do not offset the limited history.
Composer build tooling is present, but no security-scanning tool was detected. That is a modest transparency gap for a payment-related SDK, though it is not evidence of unsafe code by itself.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a maintenance and transparency gap for software handling payment integrations.
This release is explicitly a prerelease, and all recent releases are prereleases. That signals an evolving API and greater compatibility risk for dependents.
The single workflow was fully audited, uses read-only permissions, and has no untrusted checkout or injection findings. However, all four analyzed action references are unpinned, leaving them exposed to upstream reference changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0||^2.0 | — | — |
psr/simple-cache Version ^2.0||^3.0 | — | — |
php-http/discovery Version ^1.9.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.