The package has clear documentation, tests, a matching repository, and recent releases. Maintenance is concentrated in one contributor, and the repository has no security policy or scanning, so continuity and security transparency remain concerns.
68%
Total Score
67
94
50
The package runs post-install and post-update Composer scripts, which increase installation-time execution surface and warrant extra scrutiny when adopting updates.
One contributor made all 5 commits in the last 3 months, leaving no demonstrated second contributor to provide maintenance continuity. Organization ownership offers some handoff capacity but does not remove the observed concentration.
The repository has 5 commits in the last 3 months, showing recent work, but all activity is concentrated in a single active maintainer.
Composer build tooling is present, but no security scanning tools are detected, leaving an avoidable gap in the project's security hygiene.
The repository has no security policy or documented security-reporting path, reducing transparency for handling vulnerabilities in a payment integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.2 | — | — |
firebase/php-jwt Version ^6.4 || ^7.0 | — | — |
magento/framework Version >=101 | — | — |
magento/module-sales Version >=101 | — | — |
php-http/curl-client Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.