Clear documentation, a matching repository, and a small dependency set make integration straightforward. The project is licensed and not deprecated, but its recent inactivity warrants pinning this release.
63%
Total Score
50
100
94
75
The registry and repository are owned by the same individual, so there is no ownership mismatch. Individual backing is consistent but provides less maintenance redundancy than an organization-backed project.
The package has 22 releases since March 2013, but none in the last 12 months; its latest release was about 3 years and 8 months ago. This materially raises abandonment and compatibility risk.
There were no commits and no active maintainers in the last 3 months. Combined with no releases in the last year, this is the clearest sign of slowing maintenance.
The repository has no security policy. That is a transparency gap for a package handling payment notifications, although Dependabot provides some compensating security tooling.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, both action references are unpinned, leaving a modest supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.2 || ^7.0 | — | — |
symfony/event-dispatcher Version ^4.3 || ^5.0 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.