The package lacks a security policy and repository security scanning, leaving maintenance safeguards unclear. Its MIT license, focused dependency surface, and matching repository provide useful transparency.
40%
Total Score
50
100
88
83
The repository is owned by an individual account rather than an organization, providing limited visible project backing. The matching package and repository identity partly compensate for that concern.
The last release was in April 2018, with no releases in the past 12 months and only seven releases overall. This long gap materially raises abandonment risk.
There were no commits or active maintainers in the past three months, consistent with the release-history evidence of prolonged inactivity.
Composer build tooling is present, but no security scanning tools were detected. For a payment integration package, that is a meaningful maintenance and transparency gap.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities in payment-related code.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.