The single-maintainer project has no security policy and uses a proprietary license, limiting transparency and adoption flexibility. A README, changelog, release notes, and stable version provide useful documentation, but do not offset the age of the codebase.
38%
Total Score
50
64
50
Only two releases were published, both in August 2017, with no releases in the last 12 months and no newer activity observed. This strongly raises abandonment risk for a payment integration.
The manifest declares a proprietary license and a LICENSE file is present in both the package and repository, so this is licensed rather than an unlicensed release. The proprietary terms may still constrain dependency use and transparency.
One registry maintainer is consistent with a small project, but the repository owner is an individual rather than an organization, leaving little visible maintainer redundancy after years without activity.
Composer build tooling is present, but no security scanning tooling was detected. This is a modest supply-chain hygiene gap, not evidence that the release is unsafe by itself.
The repository is not archived, which avoids the strongest abandonment signal, but its last push was August 18, 2017 and therefore does not show ongoing maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.