Clear licensing, extensive documentation, tests in the source repository, and a security policy improve transparency. The single publisher and absent security scanning leave less independent evidence for long-term maintenance.
62%
Total Score
50
81
100
Only one registry publishing account is listed, which creates some continuity risk. The linked repository uses the same QBitFlow identity, providing partial context but not a broader maintainer base.
The package was released today and has only one release, so there is no established release cadence or long-term maintenance record yet.
The repository shows no commits or active maintainers in the last three months. Because the package is newly published, this is limited evidence rather than proof of abandonment, but it leaves maintenance capacity unproven.
Composer build tooling is present, but no security scanning tools were detected, reducing independent assurance for a payment-processing SDK.
Version 2.1.0 is a stable, non-prerelease major-version release, although the release notes explicitly document breaking changes despite the minor version bump.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
psr/http-client-implementation Version ^1.0 | — | — |
psr/http-factory-implementation Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.