Licensing, documentation, and release notes are clear. The package is deprecated in favor of paypal/paypal-server-sdk, so new integrations should use that replacement instead.
10%
Total Score
50
100
40
50
Packagist marks the entire package as abandoned and names paypal/paypal-server-sdk as its replacement. This directly indicates that developers should not start new dependencies on this package.
The package has had no registry release in more than eight years, despite 22 releases overall. This is strong evidence that maintenance has stopped.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the abandoned status rather than active support.
The linked repository is archived, confirming that the project is no longer intended for active maintenance. Its last push was more than three years ago.
The repository has no security policy. This is a transparency gap, although the stronger abandonment indicators already determine the release's status.
| Title | Versions | Severity |
|---|---|---|
CVE-2017-6099 paypal/merchant-sdk-php is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 3.0.0 - 3.12.0. | 3.0.0 - 3.12.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
paypal/sdk-core-php Version 3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.