A single organization contributor has made only two commits in the last three months, and all four workflow actions are unpinned. The package is licensed, tested, documented, and has release notes, which supports adoption despite its early maturity.
62%
Total Score
67
100
78
67
The package is brand new, with two releases on the same day and no established release cadence. This limits evidence of sustained maintenance but does not by itself indicate abandonment.
One contributor made 100% of the recent commits. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Only two commits were made in the last three months by one active maintainer. Recent activity is present, but the small volume provides limited evidence of sustained maintenance capacity.
The repository name does not match the package name and its README does not mention this package. Although the repository clearly contains the module's files, the missing explicit package reference weakens source-to-artifact traceability.
Composer is used for builds, but no security scanning tools are reported. The missing scanning coverage is a maintenance and transparency gap, though it is not severe on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
payzum/omnipay-payzum Version ^0.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.