The short README, absent tests, and missing security policy limit confidence for a payment integration. Organization backing and matching repository metadata provide some accountability, but the project has not shown recent maintenance.
38%
Total Score
50
63
50
The package has had only two releases, with the latest published in October 2021 and none in the last 12 months. That long period without releases is a substantial abandonment concern for a payment integration.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the absence of releases since October 2021. This indicates no current maintenance capacity.
The artifact contains license files, but the detected CC0-1.0 license does not match the declared OSL-3.0 and AFL-3.0 licenses. The release is not license-transparent enough to treat the declarations as unambiguous.
The linked repository has no security policy. That is a meaningful transparency gap for a plugin handling payment-related integration, though it is not evidence of a security defect by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^102.0.0|^103.0.0 | — | — |
magento/module-sales Version ^100.0.0|^101.0.0|^102.0.0|^103.0.0 | — | — |
magento/module-payment Version ^100.0.0 | — | — |
magento/module-checkout Version ^100.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.