Official PHP Pingen SDK for API V2
82%
Total Score
80
100
89
80
All recent commits came from one contributor, so maintenance could be disrupted if that person becomes unavailable; the repository is organization-owned, but no second active contributor is shown.
Only 1 commit was made in the last 3 months by 1 active maintainer; recent releases and two merged pull requests provide some compensating evidence, but direct development activity is thin.
The repository has only 3 stars and 8 forks, indicating limited public adoption, but popularity is supporting evidence and does not outweigh the active release and repository history.
Composer build tooling is present, but no security-scanning tools are reported, leaving a modest gap in automated supply-chain hygiene.
The repository has no security policy, which makes vulnerability reporting and disclosure expectations less transparent for a package handling API integrations.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10982 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. pingencom/pingen2-sdk-php is vulnerable to Observable Timing Discrepancy in versions 2.10.0 - 2.19.1. | 2.10.0 - 2.19.1 | Low |
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
league/oauth2-client Version ^2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.