The package has a stable release with tests, a README, release notes, and an Apache-2.0 license. Its registry status and source repository indicate that this release line is no longer suitable for new dependencies; use paypal/paypal-server-sdk instead.
12%
Total Score
100
100
42
83
Packagist marks the entire package as abandoned and names paypal/paypal-server-sdk as its replacement, which is a severe adoption risk.
The package has only three releases, with no release in the last 12 months and its latest registry release in September 2021, indicating a long period without published updates.
The linked PayPal repository is archived, so active maintenance and future fixes should not be expected even though it was pushed in November 2024.
The repository name does not match the package name and its README does not mention the exact package, creating some uncertainty about package-to-repository alignment despite the matching PayPal organization.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented; this is secondary to the package's explicit abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
paypal/paypalhttp Version 1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.