The package includes readable documentation, tests, release notes, and an MIT license file. GitHub Actions need tighter hygiene because every referenced action is unpinned and the audit found high-confidence template-injection patterns.
58%
Total Score
67
100
88
75
Post-install and post-update scripts run during dependency operations, adding operational complexity for consumers, but this is not severe on its own for a plugin package.
The package has 61 releases since March 2021, but none in the past 12 months and its latest release was in November 2024, indicating materially slowed maintenance.
All recent repository activity comes from one contributor, creating concentration risk; organization backing provides some ability to hand off maintenance but does not show active backup contributors.
Only one commit was recorded in the past three months, showing weak current maintenance activity for a payment integration.
The repository uses Composer and Make, but no security-scanning tools were detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mollie/mollie-api-php Version 2.40.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.