This is a mature, stable package with a release history spanning about 7 years, three releases in the last 12 months, a current stable major release, an unarchived repository, and clear package scaffolding including a README, tests, changelog, and license file. The organization-backed repository and README reference support package identity despite the repository name mismatch. However, the repository shows no commits or active maintainers in the last 3 months, has no security scanning or security policy, and has negligible popularity, creating meaningful maintenance and transparency concerns. It is usable as a dependency, but adopters should verify ongoing compatibility and support before relying on it for critical payment flows.
72%
Total Score
67
100
89
90
The repository records zero commits and zero active maintainers during the last 3 months. This is a meaningful maintenance concern, although the recent release history and current unarchived state partly compensate for it.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This may reflect a quiet, stable project, but it also provides no evidence of an active support channel.
The repository has zero stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but these counters provide little external validation or community signal.
Composer build tooling is present, but no security scanning tools are configured. The missing scanning coverage is a genuine supply-chain hygiene gap for a payment integration.
The repository has no security policy. For a package handling payment integration code, this reduces transparency around vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0.0 | — | — |
omnipay/common Version ^3.2 | — | — |
craftcms/commerce Version ^5.0.0 | — | — |
craftcms/commerce-omnipay Version ^4.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.