The Apache-2.0 license, tests, and release notes improve transparency. A single runtime dependency keeps the package simple, but no security policy reduces ongoing assurance.
32%
Total Score
50
38
50
The package includes a README, tests, and release notes, but the README explicitly says the SDK is deprecated and will receive no new features or support. That makes this more than a cosmetic documentation gap.
This release was the package's only release, published about three years ago, with no releases in the last 12 months. The absence of subsequent releases strongly indicates abandonment for a maintained SDK.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's deprecation notice and indicating no current maintenance capacity.
The repository name does not match the package name and its README does not mention this package, so the linked source may not clearly belong to the published package.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This adds an assurance gap for an SDK handling payment integrations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
paypal/paypalhttp Version 1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.