It has a clear MIT license, tests, and a matching organization-owned repository. The minimal README and lack of security tooling provide limited guidance for evaluating or integrating it; pin this version and verify it against your payment flow.
47%
Total Score
50
100
71
83
This is the package's only release, published about 4 years and 10 months ago, with no releases in the last 12 months. That provides strong evidence of abandonment risk, despite the stable 1.0.0 version.
The repository has had zero commits and zero active maintainers in the last 3 months, and its last push was in November 2021. The absence of recent maintenance materially increases the risk that defects or platform changes will go unanswered.
Tests are present in both the artifact and repository, which supports basic project maturity, but the README is only 18 characters and offers little integration guidance. The missing changelog is normal packaging practice and is not a concern by itself.
Composer build tooling is present, but no security scanning tools were detected. That is a modest supply-chain hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy, leaving no documented process for reporting vulnerabilities. This is a transparency gap, although it is less significant than the package's long maintenance pause.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
paytic/omnipay-twispay Version ^2.0|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.