The repository has tests, a README, and a matching MIT license, but its 30 runtime dependencies and absent security policy add maintenance overhead. Its repository does not name this package, so provenance is less clear.
42%
Total Score
50
50
75
50
The latest registry release was nearly 10 years ago, with no releases in the last 12 months. This is strong evidence that the published package is stale.
The package declares 30 runtime dependencies across payment providers, frameworks, and database integrations. That broad dependency surface increases compatibility and maintenance burden for an old release.
The package uses post-install and post-update Composer scripts. These require execution during installation, adding some operational exposure, but lifecycle scripts are common in this ecosystem and no harmful behavior is shown here.
There were no commits or active maintainers in the last 3 months, although the repository was pushed in January 2023. Recent maintenance capacity is therefore weak.
The linked repository name does not match the package name and its README does not mention the package, making it less clear that this repository directly owns the published artifact.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
payum/payum Version ^1.3 | — | — |
doctrine/orm Version ^2.5 | — | — |
omnipay/paypal Version ^2 | — | — |
omnipay/stripe Version ^2 | — | — |
klarna/checkout Version ^4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.