Its README, changelog, release notes, and license make the module easier to evaluate, but the release is explicitly described as unsuitable for production. The organization-owned repository is not archived, yet it shows no recent maintenance or security policy.
32%
Total Score
50
70
50
This package has only one release, published about 8 years and 9 months ago, with no releases in the last 12 months. That strongly indicates abandonment risk for a production dependency.
There were no commits and no active maintainers in the last 3 months, consistent with a project that has not been maintained since its original release. This leaves compatibility and defect-fix risk unresolved.
The repository has one open issue and no issues or pull requests were created or closed in the last month. This adds to the evidence of inactivity, though the broader abandonment concern is already reflected by the release and commit history.
The source repository has no security policy. For a payment integration, that is a meaningful transparency and vulnerability-reporting gap, even though it does not by itself establish a security defect.
The registry presents v1.0.0 as a stable major release, but the release documentation identifies it as a pre-release that should not be used in production. That warning materially reduces confidence in this version.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
payone-gmbh/magento-1 Version ^4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.