The package has a clear MIT license, useful documentation, tests, and a matching source repository. Its six-year absence of releases and commits leaves maintenance and compatibility risk high.
46%
Total Score
50
100
78
88
The package has had no release in over five years, despite 13 releases by October 2020. This is a substantial maintenance and compatibility concern for a payment gateway.
There were no commits and no active maintainers in the repository during the last three months, consistent with no activity since October 2020. This is strong evidence of abandonment risk.
The repository has one star, no forks, and no watchers. Low popularity is only supporting evidence, but it provides little indication of a broad community that could sustain the package.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap, while the package's stronger concern remains its lack of maintenance.
The repository has no security policy. This weakens vulnerability-reporting transparency for a payment integration, though it is not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
omnipay/common Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.