The repository has seen no commits or releases for about five years, which is a serious concern for a payment-processing dependency. Its MIT license, tests, README, and non-deprecated status provide useful transparency but do not offset the stalled maintenance.
42%
Total Score
50
100
72
75
The package has had only 3 releases, all concentrated on 21 April 2021, with no releases in the last 12 months. That long release gap materially raises abandonment risk for a payment library.
There were zero commits and zero active maintainers in the last 3 months, consistent with roughly five years without visible repository updates. This is strong evidence of stalled maintenance.
The repository is owned by an individual account rather than an organization, so there is no visible organizational backing to compensate for the thin maintenance record.
The repository has 0 stars and 0 forks, with 1 watcher. Popularity is only supporting evidence, but these counters provide no meaningful community signal to offset the maintenance gap.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap, while the much larger concern remains the lack of maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-http/discovery Version ^1.12 | — | — |
php-http/guzzle7-adapter Version ^0.1 | — | — |
muhammadaldan/omnipay8-common Version 1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.