Healthy and suitable to depend on. It has frequent releases, recent activity from four contributors, clear repository ownership, and a substantial tested package; the main caveats are no security policy and a deployment workflow with write permissions.
88%
Total Score
100
94
80
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest transparency and assurance gap for a payment-capable e-commerce plugin.
No repository security policy was found, so users have limited documented guidance for reporting vulnerabilities in an e-commerce package.
The deployment workflow has top-level write token permissions, which expands CI compromise impact even though the workflow has no separately detected dangerous patterns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/omnipay Version ^3.2 | — | — |
omnipay/paypal Version ^3.0 | — | — |
omnipay/stripe Version ^3.0 | — | — |
hashids/hashids Version ^4.0|^5.0 | — | — |
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.