This release is usable but carries meaningful maturity and continuity concerns. It is a stable, non-deprecated package backed by an organization-owned repository that was pushed recently, uses build tooling, and has a clean workflow-risk profile. However, the package is extremely new with only two releases, has no tests or changelog, has only one active contributor responsible for all recent commits, lacks a security policy, and uses top-level write permissions in its workflow. The repository backing and organization ownership partially mitigate the narrow maintainer base, but the limited history means developers should adopt it with monitoring and a contingency plan.
62%
Total Score
70
100
78
75
The package includes a substantive README and the repository uses GitHub Releases, but neither the artifact nor repository contains tests or a changelog. For a payment integration, the absence of visible tests is a genuine maintenance and verification gap.
Only two releases exist and both were published within the same day, leaving almost no observed maintenance history or evidence of sustained release cadence.
One contributor made all three commits in the last three months, creating a narrow operational bus factor. Organization ownership partly mitigates handoff risk, but no second active contributor is evidenced.
Three commits occurred in the last three months, showing recent maintenance, but all activity is concentrated in a single active maintainer. The activity is positive but still thin for a payment integration.
There are no open issues or pull requests and no activity in the last month. This is ambiguous for a newly published repository: it provides no evidence of community engagement, but it also does not show unresolved maintenance backlog.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.