A clear README, tests, and an MIT declaration make the package easier to inspect. The payment code has had no updates for years, with little visible project support, so pinning this release carries substantial maintenance risk.
42%
Total Score
25
75
83
The package has only one release, published about 5 years and 10 months ago, with no releases in the last 12 months. That strongly suggests abandonment despite the stable version.
The repository recorded no commits and no active maintainers in the last 3 months, while its last push was in November 2020. This is strong evidence that maintenance has stopped.
The registry lists one maintainer. A single publisher creates limited continuity if that person becomes unavailable, and there is no organization backing shown to compensate for it.
The repository has 0 stars, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these values provide little external evidence of adoption or review.
The repository has no security policy. For a payment integration, this reduces transparency around vulnerability reporting and response, and no other provided signal compensates for that gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.