Usable with caveats: the package is actively published and backed by an organization, but it is very young, has only two releases, and recent repository work is limited to one contributor. The absence of tests and a security policy adds maintenance risk for a payments SDK.
62%
Total Score
70
100
72
90
A substantial README and changelog are present, and the repository uses GitHub Releases, but neither the package nor repository contains tests. For a payments SDK, that missing validation is a meaningful maintenance gap.
The package is only 65 days old and has two releases, with about 66 days between releases. This provides limited evidence of long-term maintenance or release consistency.
All two recent commits came from one contributor, concentrating maintenance responsibility. Organization backing partly offsets the risk because the project can potentially hand work to another maintainer.
Only two commits were recorded in the last three months, with one active maintainer. Recent work exists, but the pace offers limited evidence of sustained maintenance.
There are no open issues or pull requests and no recent issue or pull-request activity. This does not show unresolved problems, but it also provides little evidence of community review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.