The repository is tiny and has no security scanning, while a single maintainer limits continuity. MIT licensing, a useful README, and release notes improve transparency but do not offset the maintenance risk.
42%
Total Score
0
70
50
The package has had no releases in over seven years, with all three releases clustered on 10 May 2019. This strongly indicates abandonment risk despite the stable current version.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving no evidence of ongoing maintenance.
The repository has 0 stars and 0 forks, with only 1 watcher. Popularity is not decisive, but these counters provide no supporting evidence of community adoption or review.
The linked repository has no security policy, reducing transparency around vulnerability reporting and response for a package that integrates with a payment API.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gocardless/gocardless-pro Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.