Clear documentation, tests, changelog, and release notes make integration easier. The repository is actively updated and organization-backed, though it is still young and all recent commits come from one contributor; no security policy or scanning is visible.
78%
Total Score
83
100
88
88
The package is only 47 days old and has two releases, with a median interval of about 48 days. That is too little history to demonstrate long-term maintenance, though the second release arrived with substantive fixes.
All 27 recent commits came from one contributor. This creates concentration risk, although the organization-owned repository provides some capacity to hand maintenance off.
Composer build tooling is present, but no security-scanning tooling was detected. The missing scanning is a modest transparency and hygiene gap rather than evidence of unsafe code.
The repository has no security policy. For a payment integration, that reduces the clarity of vulnerability-reporting and response procedures.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
paradoxlabs/cybersource Version ^4.0.0 | — | — |
hyva-themes/magento2-theme-module Version ^1.3.11 | — | — |
hyva-themes/magento2-hyva-checkout Version ^1.3 | — | — |
hyva-themes/magento2-payment-icons Version >=2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.