The package has a clear README, an MIT license, and no install-time scripts. It has no tests or security policy, and its workflow uses three unpinned actions, increasing maintenance and build-integrity concerns.
55%
Total Score
50
100
86
75
This is the only release, published about 3 years ago, with no releases in the last 12 months. That is strong evidence of limited ongoing maintenance for a payment integration.
The repository had no commits and no active maintainers in the last 3 months, consistent with the long release gap and raising abandonment risk.
The repository has no security policy. For a package handling payment transactions and credentials, this reduces transparency around reporting and response.
All 3 analyzed action references are unpinned, which weakens build reproducibility. The audit found no untrusted checkouts, injection issues, or high-confidence dangerous findings, limiting this to a hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version >=9.0 | — | — |
illuminate/contracts Version >=9.0 | — | — |
mnastalski/przelewy24-php Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.