The README is useful for a payment integration, and the package has few runtime dependencies and no install-time scripts. Its proprietary licensing, absent security policy, and lack of security tooling limit transparency, while the project remains very new.
58%
Total Score
50
100
71
75
The manifest explicitly declares a proprietary license, so the release is licensed, but it does not provide the transparency or reuse rights normally expected from an open-source dependency.
The package is only 55 days old, with four releases clustered over roughly four days and no demonstrated longer-term maintenance record. The rapid initial release activity is mildly positive but does not establish durability.
One contributor made 100% of the six recent commits, leaving the project dependent on a single person for continuity and review.
Six commits occurred in the last three months, showing some activity, but all activity is concentrated in one active maintainer.
Composer is used for builds, but no security scanning tools were detected. For a payment SDK, the missing security tooling is a meaningful hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.