A README, tests, matching MIT license, and organization-backed repository provide useful transparency. Maintenance has stopped for about four years, while the project has one registry maintainer and no security policy or scanning.
58%
Total Score
50
100
75
50
The package has 35 releases but none in the last 12 months, and its latest release was about four years ago. This strongly lowers confidence in ongoing maintenance.
There were no commits and no active maintainers in the last three months, providing direct evidence that development is currently inactive.
Only one account has registry publishing access, which is a modest continuity risk. The organization-backed repository provides some compensation, but does not demonstrate active maintenance.
There were no new issues, pull requests, or merges in the last month. With no recent commits, this is consistent with inactivity rather than evidence of active stability.
Composer build tooling is present, but no security scanning tools were detected. This is a maintenance and transparency gap, though not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
omnipay/common Version ^3.0 | — | — |
php-http/guzzle6-adapter Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.