The package includes a clear README, changelog, Composer build tooling, and CodeQL scanning, with organization backing. Its unpinned workflow actions, missing security policy, and recent lack of repository commits leave meaningful maintenance and release-process concerns.
64%
Total Score
67
100
93
67
The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign that maintenance has recently paused.
There were no new or closed issues and no pull requests in the last month, while four issues remain open; this provides little evidence of active issue handling.
No security policy was found in the repository, reducing transparency about vulnerability reporting for a payment integration.
Version 0.5.4 is not a stable major release, so compatibility expectations are lower than for a 1.x package; it is nevertheless not a prerelease.
The single workflow was fully analyzed with no untrusted checkout or script-injection findings, but all 8 action references are unpinned and the workflow grants top-level write permissions. These are workflow-hygiene concerns, not severe risks on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
payu-mea/payu-mea-sdk-php Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.