The package includes tests, a README, matching Apache-2.0 licensing, and a repository that is not archived. Its single release was nearly two years ago, with no recent commits and no security policy, so future maintenance is uncertain.
58%
Total Score
50
80
75
This is the package's only release, published nearly two years ago, with no releases in the last 12 months. That materially raises abandonment risk despite the repository still being available.
Only one registry maintainer is listed, leaving a thin publishing and maintenance base. The matching user-owned repository confirms ownership but does not provide contributor redundancy.
The repository recorded no commits and no active maintainers in the last three months, providing no evidence of current maintenance capacity.
The repository has no security policy, which reduces transparency for a package handling payment-token decoding. Its tests and documented usage provide some compensating project structure but do not replace a reporting process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^4.1|^5.0|^6.0|^7.1 | — | — |
phpseclib/phpseclib Version ^3.0 | — | — |
spomky-labs/php-aes-gcm Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.