It has a clear MIT license, documentation, tests, release notes, and a repository tied to the package. Its workflow references are unpinned and the repository has no security policy, leaving limited maintenance and build transparency.
15%
Total Score
0
50
50
Packagist marks the entire package as abandoned, with no replacement supplied. This is a severe adoption risk for a payment integration.
The latest release was in August 2022, with no releases in the subsequent 12 months covered by the signal. This indicates the package has been inactive for several years.
The repository recorded zero commits and zero active maintainers in the last three months. Together with the archived repository and abandoned package status, this indicates no current maintenance capacity.
The linked repository is archived and was last pushed in January 2023, so the source is no longer actively maintained. Archival status is a severe risk for a dependency.
The repository has no security policy. That weakens vulnerability-reporting transparency, although the license, tests, and release documentation provide some compensating project structure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^3.2 | — | — |
guzzlehttp/psr7 Version ^1.6 || ^2.0 | — | — |
craftcms/commerce Version ^3.1.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
multisafepay/php-sdk Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.