The project has had no commits or active maintainers in the last three months, and its only release is still v0.1.0. It includes tests, a clear README, and an MIT license, but the workflow uses two unpinned actions and the repository has no security scanning.
62%
Total Score
50
100
78
75
The repository is owned by a user account rather than an organization, so the available ownership evidence does not show broader organizational maintenance capacity.
Only one release exists over roughly 126 days, so there is little evidence of sustained release maintenance or maturity.
There were zero commits and zero active maintainers in the last three months, which is concerning for a package that integrates with a payment API and has only one release.
There are no open issues or pull requests and no recent activity. With no reported problems this is not independently dangerous, but it also provides no evidence of an active support process.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but this provides no external adoption signal for a payment SDK.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.