The project has one registry maintainer and no security scanning, while its README and release notes provide basic usage context. It is not deprecated or archived, but the long abandonment gap makes this release a poor new dependency.
42%
Total Score
50
81
75
This is the package's only release, published over 10 years ago, with no releases in the last 12 months. That is strong evidence of abandonment despite the stable 1.0.0 version.
Only one registry account has publishing access. Because the project is user-owned rather than organization-backed, this leaves limited visible maintenance capacity.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the package's prolonged lack of releases. Its repository is not archived, but that does not compensate for the absent activity.
Composer build tooling is present, but no security-scanning tools were detected. This is a hygiene and maintenance gap for a package involved in payment-related integrations.
The repository has no security policy. For a package handling payment and fraud-checking integrations, this weakens transparency around reporting and response.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.