The repository has no recent commits, no security scanning, and no active issue or pull-request work. Licensing, documentation, release notes, and install hygiene are present, but they do not offset the project's abandonment signals.
12%
Total Score
67
50
83
Packagist marks the entire package as abandoned and provides paypal/paypal-server-sdk as a replacement, directly indicating that this release line should not receive future maintenance.
The latest release was published in December 2015, with no releases in the last 12 months; this release is roughly 10 years old and unlikely to receive updates.
The linked PayPal repository is archived, which is a severe abandonment signal even though it was pushed in November 2024.
The repository recorded zero commits and zero active maintainers in the last 3 months, providing no evidence of ongoing development.
There was no issue or pull-request activity in the last month, with one open issue remaining; this is consistent with a dormant project.
| Title | Versions | Severity |
|---|---|---|
CVE-2017-6215 paypal/permissions-sdk-php is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.9.1. | 0.0.0 - 3.9.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
paypal/sdk-core-php Version 3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.