The repository is not archived and the package has a stable major version with no install-time scripts. Its small codebase and Composer build tooling help, but the absence of security scanning and consumer documentation leaves little ongoing assurance.
32%
Total Score
0
40
50
Neither the package nor its linked repository declares or includes a detectable license. This creates a material legal and adoption risk for a dependency.
The latest release was published in October 2016, with no releases in the last 12 months. Nearly ten years without a release strongly increases abandonment and compatibility risk.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and reinforcing abandonment risk.
The package has no README, making integration harder for a payment extension. Missing tests and changelog files are normal for published artifacts and do not add concern here.
The project uses Composer, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap rather than evidence of immediate unfitness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
platform/foundation Version >=2.0 <5.0 | — | — |
cartalyst/composer-installers Version 1.2.* | — | — |
ondrakoupil/csob-eapi-paygate Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.