Recent maintenance has stopped, and only one release was published in the last year. The project has tests, a license file, release notes, and a matching repository, but it relies on one maintainer without repository security tooling or a security policy.
62%
Total Score
50
88
83
One registry maintainer publishes the package. That is a meaningful continuity risk for a user-owned project, although the recent release and repository activity show the maintainer is still active.
The package has 192 releases over more than six years, but only one release in the last 12 months, indicating a substantial slowdown from its earlier cadence.
The repository recorded zero commits and zero active maintainers in the last three months, which is the clearest sign that ongoing development has paused.
Composer build tooling is present, but no security-scanning tooling was detected, leaving repository assurance weaker than it could be.
The repository has no security policy, so users have no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gusapi/gusapi Version ^6.0 | — | — |
league/omnipay Version ^3.0 | — | — |
omnipay/paypal Version ^3.0 | — | — |
n1ebieski/icore Version ^8.4 | — | — |
mike182uk/paypal-ipn-listener Version ^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.