Healthy and usable for this focused payment-method package, with an active organization-backed repository and documented release. The main caveat is that recent work is concentrated in one contributor and the repository has no security policy.
78%
Total Score
67
100
89
83
The package is young at 154 days old, with three releases and a median interval of about 54 days. This shows real release activity, though the history is still too short to establish long-term stability.
One contributor accounts for all commits in the last three months, creating a thin individual contributor base. This is partly mitigated because the repository is owned by an organization that can potentially hand maintenance off.
Only one commit from one active maintainer was recorded in the last three months. The recent release is positive evidence, but the low ongoing activity leaves some abandonment risk.
Composer is used as a build tool, showing a defined package workflow, but no security scanning tools were detected. For a small package this is a transparency gap rather than a severe health failure.
The repository has no security policy. That weakens vulnerability-reporting transparency, although the package is small and no dangerous workflow behavior was detected.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
wp-pay/core Version ^4.0 | — | — |
pronamic/wp-pay-logos Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.