The package is licensed, documented, and free of install-time scripts. Its only release and repository activity date to February 2022, with one maintainer and no security scanning, so maintenance risk is substantial.
44%
Total Score
25
81
75
This is the package's only release, published in February 2022, and there have been no releases in the last 12 months. The lack of release activity over more than four years raises abandonment risk.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the package having received no visible maintenance since February 2022.
One registry maintainer is reasonable for a small personal project, but it provides little redundancy when combined with the absence of recent releases and commits.
Composer is used for the build, but the repository reports no security-scanning tools. This is a hygiene gap for a payment-gateway wrapper, though it is not evidence of compromise by itself.
The repository has no security policy, leaving no documented reporting path for vulnerabilities in a package handling payment integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ^v3.0.12 | — | — |
thepay/api-client Version ^v1.3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.