Risky to adopt: this is a single-release package with no updates for about three years and nine months, leaving maintenance uncertain. The source repository has minimal visibility, no README or security policy, and does not clearly match the package, despite having a real Magento module tree and no deprecation or install scripts.
38%
Total Score
25
50
83
Only one release exists, published about three years and nine months ago, with no releases in the last 12 months. That provides strong evidence of abandonment risk for a payment integration.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long-stalled release history. No newer activity compensates for the lack of maintenance evidence.
The manifest declares a proprietary license, so the release is explicitly licensed rather than lacking licensing information. However, this may impose usage restrictions for developers evaluating an open-source dependency.
Only one registry account has publish access, which limits publishing resilience. The repository owner is a user rather than an identified organization, so no provided backing signal compensates for the thin maintainer base.
The artifact has no README, which makes integration and operational expectations harder for consumers to verify. Missing tests and a changelog are normal packaging gaps, but the absent README is a meaningful transparency concern for a payment module.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.