The package is well documented, licensed, tested, and has a release record, but maintenance has stopped: no releases in the last 12 months and no commits or active maintainers in the last three months. There is also no security policy or automated security scanning, so pinning this version carries ongoing maintenance risk.
58%
Total Score
50
50
88
83
The repository recorded zero commits and zero active maintainers in the last three months, a strong sign that maintenance has stalled.
The package declares 18 runtime dependencies, including several payment, shipping, and integration SDKs. This is understandable for an e-commerce platform but increases maintenance and compatibility exposure.
The package has 11 releases and a typical historical interval of about 39 days, but it has had no releases in the last 12 months; this is a meaningful maintenance concern.
There are 9 open issues but no new or closed issues, pull requests, or merges in the last month, indicating limited current project activity.
Composer build tooling is present, but no security scanning tools are configured, leaving an important maintenance and vulnerability-detection gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
openpay/sdk Version 2.1.1 | — | — |
mews/purifier Version ^3.4.2 | — | — |
laravel/fortify Version ^1.11 | — | — |
guzzlehttp/guzzle Version ^7.0.1 | — | — |
laravel/framework Version ^9.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.