Lava Payment SDK
62%
Total Score
caution
Usable with caveats: maintenance is concentrated in one contributor and the workflow uses an unpinned container image.
The repository owner is an individual account, so the concentrated contributor activity is not visibly supported by an organization.
One contributor made all recent commits, leaving maintenance fully concentrated in a single person. The repository owner is an individual rather than an organization, so there is no shown organizational handoff to offset this.
Only one commit was recorded in the last three months, which is limited recent maintenance for an SDK handling payment integrations.
The repository has no security policy, reducing transparency about how payment-related vulnerabilities should be reported and handled.
All workflows use read-only permissions and the audit completed fully, but the high-confidence audit found an unpinned container image. This is a reproducibility and build-hygiene concern, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.