Healthy and actively maintained, with clear documentation, frequent releases, and an organization-backed repository. Install with caution because all recent commits come from one maintainer and the repository has a write-enabled pull-request workflow without a security policy.
76%
Total Score
88
100
100
63
One of seven workflows uses pull_request_target, which can increase the impact of untrusted pull requests even though no untrusted checkout or script injection was detected.
Only one contributor made all four recent commits, concentrating maintenance responsibility and creating a real continuity risk. Organization backing provides some handoff capacity, but no second active contributor is shown.
No security policy is present, leaving vulnerability-reporting expectations undocumented for a payment-related integration.
Six workflows omit top-level permissions and one workflow grants top-level write access. The repository's organization backing and absence of detected script injection partly reduce concern, but the permissions posture is still a hygiene weakness.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.