The linked repository is not archived, and the package includes a clear README, changelog, and matching MIT license. Its repository does not identify the package in the README, and it has no security policy or recent development activity.
42%
Total Score
25
100
67
75
This is the package's only release, published about two years and six months ago, with no releases in the last 12 months. That leaves little evidence of ongoing maintenance for a payment integration.
There were no commits and no active maintainers in the last three months, despite the repository being collected successfully. Combined with the single-release history, this is strong evidence of abandonment risk.
The repository is owned by an individual account rather than an organization. This is not inherently unhealthy, but it provides less visible backing for a package with no recent activity.
The repository name does not match the package name and its README does not mention the package. That raises uncertainty about whether the linked repository is the package's intended home.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counts provide no community signal to compensate for the inactive maintenance record.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
gingerpayments/ginger-php Version >=2.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.